VORANT. Threat Intelligence Sign in Get the full feed

ShareFile Flaws Chain to RCE via Webshells

high vulnerability financial-serviceshealthcaretechnology

Chained authentication bypass and RCE vulnerabilities in Progress ShareFile allow attackers to plant ASPX webshells, with public PoC code now available.

CISA/MS-ISAC issued an advisory covering two vulnerabilities in Progress ShareFile's Storage Zones Controller (SZC) component that, when chained, enable remote code execution. CVE-2026-2699 is an authentication bypass caused by improper handling of HTTP redirects, granting access to the admin interface, while CVE-2026-2701 allows abuse of file upload and extraction functionality to place malicious ASPX webshells in the application's webroot. Affected versions are those prior to 5.12.4.

WatchTowr has publicly released proof-of-concept code and a demonstration for both vulnerabilities, significantly increasing the likelihood of exploitation attempts against internet-facing ShareFile deployments. Given ShareFile's use in finance and healthcare for secure document exchange and compliance workflows, successful exploitation could expose sensitive client and business data. Organizations should prioritize patching to 5.12.4 or later, along with standard vulnerability management, network segmentation, and exploit protection controls.

Mentioned in this report

Vulnerabilities CVE-2026-2699templatedCVE-2026-2701

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-progress-sharefile-could-allow-for-remote-code-execution_2026-030

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free