Skip to content
Progress SoftwareCVE-2026-16139

Progress Software ShareFile Storage Zones Controller: remote code execution

High7.2CVE-2026-16139 · Published Aug 17, 2026 · updated Sep 2, 2026

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

Progress Software advisory

Affected versions

PackageAffectedFixed in
ShareFile Storage Zones Controller
Product
<= 5.12.5No fix yet
>= 6.0.0, <= 6.0.2No fix yet
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software ShareFile Storage Zones Controller: path traversal
High7.2Aug 17
Progress Software ShareFile Storage Zones Controller: unsafe deserialization
High8.0Aug 17
Progress Software WhatsUp Gold: remote code execution
High8.8Aug 12
Progress Software WhatsUp Gold: cross-site scripting
High8.0Aug 12
Progress Software WhatsUp Gold: improper authorization
Medium4.3Aug 12
Progress Software WhatsUp Gold: path traversal
Medium6.8Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.