# ShareFile Flaws Chain to RCE via Webshells

Published: 2026-04-02 · Severity: high · Sectors: financial-services, healthcare, technology
Canonical: https://vorant.io/reports/01eec6e5-c9d5-56f2-9005-47da019909b1/sharefile-flaws-chain-to-rce-via-webshells

> Chained authentication bypass and RCE vulnerabilities in Progress ShareFile allow attackers to plant ASPX webshells, with public PoC code now available.

CISA/MS-ISAC issued an advisory covering two vulnerabilities in Progress ShareFile's Storage Zones Controller (SZC) component that, when chained, enable remote code execution. CVE-2026-2699 is an authentication bypass caused by improper handling of HTTP redirects, granting access to the admin interface, while CVE-2026-2701 allows abuse of file upload and extraction functionality to place malicious ASPX webshells in the application's webroot. Affected versions are those prior to 5.12.4.

WatchTowr has publicly released proof-of-concept code and a demonstration for both vulnerabilities, significantly increasing the likelihood of exploitation attempts against internet-facing ShareFile deployments. Given ShareFile's use in finance and healthcare for secure document exchange and compliance workflows, successful exploitation could expose sensitive client and business data. Organizations should prioritize patching to 5.12.4 or later, along with standard vulnerability management, network segmentation, and exploit protection controls.

## Mentioned in this report

- Vulnerabilities: CVE-2026-2699 (templated), CVE-2026-2701

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-progress-sharefile-could-allow-for-remote-code-execution_2026-030

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/01eec6e5-c9d5-56f2-9005-47da019909b1/sharefile-flaws-chain-to-rce-via-webshells.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
