CSIDB logo
Incident

Progress Software

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-12 00:52

Linked entities

Victim
Progress Software
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Jul 2026

Summary

Progress Software temporarily suspended access to its ShareFile Storage Zones Controller after detecting a credible external security threat tied to a high‑severity path traversal vulnerability affecting versions 5.x and 6.x, restored the service after releasing patched versions 5.12.5 and 6.0.2, and stated there is no evidence of unauthorized access to customer data. The company noted it has experienced prior security issues with its MOVEit offerings and is working to prevent further exposure.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On July 10, 2026 Progress Software detected what it described as a credible external security threat targeting its ShareFile Storage Zones Controller component, prompting the company to temporarily suspend the service. ShareFile is Progress’ flagship enterprise file‑sharing offering, and the Storage Zones Controller provides customers with private data storage capabilities. The suspension lasted four days, during which access to the Storage Zones Controller was unavailable to users. Progress confirmed that the incident stemmed from the exploitation of a high‑severity path traversal vulnerability affecting Storage Zones Controller versions 5.x and 6.x. Service was restored on July 14 after the company had developed and released patched versions of the software.

Progress released the patched versions 5.12.5 and 6.0.2, stating that once customers applied these updates their Storage Zones Controllers would return to operational status. The company told Infosecurity that there was no evidence of unauthorized access to any ShareFile customer account or data and that it had not identified any active threat associated with the incident. Progress chose not to disclose a CVE identifier at the time, explaining to BleepingComputer that it was delaying publication to allow customers sufficient opportunity to patch before details became publicly available to potential threat actors. The response included communication with customers about the availability of the patches and confirmation that the service had been resumed after the suspension period.

Progress noted that it has experienced prior security incidents, including the 2023 breach of its MOVEit Transfer product that was exploited in widespread ransomware attacks and a critical vulnerability reported in MOVEit Automation in April 2026 that caused further disruptions. These historical events were mentioned only as contextual background and were not linked to the ShareFile Storage Zones Controller incident. The narrative concludes with the confirmation that the service was operational again after the patch deployment and that no customer data compromise was identified based on the information available at that time.

Sources

Sources available to members: 1 source.

CSIDB