INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Progress ShareFile Pre-Auth RCE Chain Vulnerability

| 2026-04-02 13:33 CRITICAL HIGH
Executive Summary AI-generated
The ShadowServer Foundation has identified a critical vulnerability in Progress ShareFile, an enterprise-grade secure file transfer solution. The flaw allows attackers to chain two vulnerabilities - authentication bypass and remote code execution - to enable unauthenticated file exfiltration from affected environments. Researchers at offensive security company watchTowr discovered the issue in branch 5.x of Progress ShareFile, which has been addressed in version 5.12.4. This vulnerability can be exploited by attackers to gain pre-authentication access and execute malicious code on the server. The ShadowServer Foundation is aware of the potential threat and has taken steps to mitigate it, but its exact impact remains unclear due to the large number of affected Storage Zone Controller instances exposed on the public internet.
Technical Mitigations AI-generated
* Implement secure authentication and authorization mechanisms, such as multi-factor authentication (MFA) and role-based access control (RBAC), to prevent unauthorized access to the Storage Zones Controller (SZC) component. * Regularly update and patch Progress ShareFile versions to ensure that known vulnerabilities are addressed before they can be exploited by threat actors. * Monitor system logs and network traffic for suspicious activity, such as unusual file transfers or changes in storage zone configurations, which could indicate a Pre-Authenticated Remote Code Execution (Pre-ARC) attack. * Conduct automated pentesting and vulnerability scanning of systems running vulnerable versions of Progress ShareFile Storage Zone Controller to identify potential entry points for attackers.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-2701CVE-2026-2701 CVE-2026-2699CVE-2026-2699
Target & Sectors
Global Scope
Incident Timeline
‎February 2026
Threat actors used watchTowr's Python PoC to chain Authentication Bypass WT-2026-0006 and Remote Code Execution WT-2026-0007 attacks.
vulnerability CVE-2026-2701
tactic Remote Code Execution
general_metric 2701 Remote Code Execution
tactic T1059.006 - Python
organisation the Authentication Bypass
organisation Timeline Date
organisation Detail
organisation Progress Security Team
‎14th February 2026
Threat actors used a pre-authentication Remote Code Execution (RCE) vulnerability in the ShareFile system to gain unauthorized access.
‎18th February 2026
Threat actors exploited a pre-authentication Remote Code Execution (RCE) vulnerability in the ShareFile system to gain unauthorized access.
‎February 18
Threat actors used a pre-auth RCE vulnerability in Progress ShareFile 5.12.4 to chain flaws discovered by watchTowr between February 6 and 13, with the full exploit confirmed on February 18.
general_metric 0006 WT-2026
general_metric 13 February
‎March 10, 2026
Threat actors exploited a pre-authentication Remote Code Execution (RCE) vulnerability in ShareFile's Progress share feature to gain unauthorized access.
infrastructure 5.12.4
‎10th March 2026
Threat actors exploited a pre-authentication remote code execution vulnerability in the Storage Zone Controller 5.12.4 by chaining it with another known flaw to gain unauthorized access.
infrastructure 5.12.4
‎March 10
Threat actors exploited vulnerabilities in Progress ShareFile 5.12.4 to target the software on March 10.
infrastructure 5.12.4
‎April 02 2026
Threat actors used a vulnerability in the Tracker software to target an exploit for CVE-2026-2701 Remote Code Execution.
vulnerability CVE-2026-2699
vulnerability CVE-2026-2701
tactic Remote Code Execution
general_metric 2701 Remote Code Execution
‎WT-2026-0007
Threat actors used a Python PoC to chain Authentication Bypass and Remote Code Execution vulnerabilities (CVE-2026-2701) in ShareFile, allowing for Pre-Authenticated Remote Code Execution.
vulnerability CVE-2026-2701
tactic Remote Code Execution
general_metric 2701 Remote Code Execution
organisation the Storage Zone Controller
organisation Post-Auth Remote Code Execution
tactic T1059.006 - Python
organisation the Authentication Bypass
‎2026/04/02
Attackers can obtain remote code execution on the server by abusing file upload and extraction functionality to place malicious ASPX webshells in the application’s webroot.
tactic Remote Code Execution
organisation Progress ShareFile
organisation Pre-Authenticated Remote Code Execution
vulnerability CVE-2026-2699
vulnerability CVE-2026-2701
infrastructure 12.3
general_metric 0007 WT-2026
organisation ShareFile
organisation Functionality
organisation The ShadowServer Foundation
organisation SolarWinds Serv-U
organisation MFT
organisation Pre-Auth RCE Chain CVE-2026-2699
organisation WT-2026-0006
organisation SZC
organisation CVE-2026
organisation DLL
organisation Content-Disposition
organisation filename="test.zip
data_breach 1 ------WebKitFormBoundary7MA4YWxkTrZu0gW
data_breach 2 ------WebKitFormBoundary7MA4YWxkTrZu0gW
data_breach 3 ------WebKitFormBoundary7MA4YWxkTrZu0gW
data_breach 123 ------WebKitFormBoundary7MA4YWxkTrZu0gW
organisation Cache-Control
organisation Content-Type
organisation Microsoft
organisation Access-Control-Allow-Origin
organisation Access-Control-Max-Age
organisation Access-Control-Allow-Headers
organisation POST
organisation OPTIONS
organisation Strict-Transport-Security
organisation X-XSS-Protection
organisation X-Frame-Options: DENY Date: Mon
organisation GMT
organisation Content-Length
organisation DOCTYPE
organisation Login.aspx
organisation Response
organisation ShareFiles
organisation SMB
organisation Progress’s
organisation ASMX
organisation PHP
organisation EAR
organisation EventArgs
organisation ActionHeader
organisation ApplicationInstance
organisation Authentication Bypass
organisation Storage Zone Controllers
organisation Hostname Hostname
organisation External Address
organisation Storage Repository
organisation API/Rest
organisation API
organisation Passphrase
organisation Storage Zone Controller
organisation UNC
organisation StorageCenter
organisation BusinessLogic
organisation GUID
organisation ContentLength
organisation Upload
organisation UUID
organisation HttpMethod
organisation UploadLogic
organisation num2
organisation null &&
organisation InputFile
organisation File7
organisation Network Share Location
organisation PoC
organisation UI
organisation HMAC-SHA256
organisation ZoneConfig
organisation AES
organisation HMAC
organisation DAG
organisation the Detection Artifact Generator
organisation WatchTowr
organisation New Progress
organisation Progress
‎WT-2026-0006
Threat actors used a Python PoC to chain Authentication Bypass WT-2026-0006 and Remote Code Execution WT-2026-0007 attacks in pre-auth RCE attacks.
tactic Remote Code Execution
tactic T1059.006 - Python
organisation the Authentication Bypass
organisation Timeline Date
organisation Detail
organisation Progress Security Team
‎2nd April 2026
Threat actors exploited vulnerabilities in ShareFile to launch pre-authentication Remote Code Execution (RCE) attacks.
Tactical Metrics
Metrics
infrastructure
​12.3
Software Version
Metrics
data_breach
2,701
Authentication Bypass Cve-2026 Remote Execution Sharefile
Metrics
infrastructure
​5.12.4
Software Version
Metrics
data_breach
1
------Webkitformboundary7Ma4Ywxktrzu0Gw
Metrics
data_breach
2
------Webkitformboundary7Ma4Ywxktrzu0Gw
Metrics
data_breach
3
------Webkitformboundary7Ma4Ywxktrzu0Gw
Metrics
data_breach
123
------Webkitformboundary7Ma4Ywxktrzu0Gw