Progress SoftwareCVE-2026-16138
Progress Software ShareFile Storage Zones Controller: unsafe deserialization
High8.0CVE-2026-16138 · Published Aug 17, 2026 · updated Sep 2, 2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ShareFile Storage Zones Controller Product | <= 5.12.5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-502
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: path traversal | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |