Progress SoftwareCVE-2026-16139
Progress Software ShareFile Storage Zones Controller: remote code execution
High7.2CVE-2026-16139 · Published Aug 17, 2026 · updated Sep 2, 2026
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ShareFile Storage Zones Controller Product | <= 5.12.5 | No fix yet |
| >= 6.0.0, <= 6.0.2 | No fix yet |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: path traversal | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |