Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
7.2
CVE-2026-16139PATCHED
progress · sharefile storage zones controller

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

Description

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

Affected Products

VendorProductVersions
progresssharefile storage zones controller0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixsharefile storagezonescert_advisory90%

References

  • https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories5d ago
[NEU] [hoch] Citrix Systems ShareFile StorageZones Controller: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-16139 | Progress ShareFile Storage Zones Controller up to 5.12.5/6.0.2 path traversal
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information
CWECWE-22, CWE-73, CWE-20
PublishedAug 17, 2026
Last enriched6d ago
Trending Score22
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-16138
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Trending: 22
HIGHCVE-2026-16137
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Trending: 22
CRITICALCVE-2026-8037EXPKEV
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 21
HIGHCVE-2026-59689
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Trending: 15
HIGHCVE-2026-59690
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 18, 2026