Progress Software
Incident posture
Linked entities
- Victim
- Progress Software
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Progress Software temporarily suspended access to its ShareFile Storage Zones Controller after detecting a credible external security threat tied to a high‑severity path traversal vulnerability affecting versions 5.x and 6.x, restored the service after releasing patched versions 5.12.5 and 6.0.2, and stated there is no evidence of unauthorized access to customer data. The company noted it has experienced prior security issues with its MOVEit offerings and is working to prevent further exposure.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 10, 2026 Progress Software detected what it described as a credible external security threat targeting its ShareFile Storage Zones Controller component, prompting the company to temporarily suspend the service. ShareFile is Progress’ flagship enterprise file‑sharing offering, and the Storage Zones Controller provides customers with private data storage capabilities. The suspension lasted four days, during which access to the Storage Zones Controller was unavailable to users. Progress confirmed that the incident stemmed from the exploitation of a high‑severity path traversal vulnerability affecting Storage Zones Controller versions 5.x and 6.x. Service was restored on July 14 after the company had developed and released patched versions of the software.
Progress released the patched versions 5.12.5 and 6.0.2, stating that once customers applied these updates their Storage Zones Controllers would return to operational status. The company told Infosecurity that there was no evidence of unauthorized access to any ShareFile customer account or data and that it had not identified any active threat associated with the incident. Progress chose not to disclose a CVE identifier at the time, explaining to BleepingComputer that it was delaying publication to allow customers sufficient opportunity to patch before details became publicly available to potential threat actors. The response included communication with customers about the availability of the patches and confirmation that the service had been resumed after the suspension period.
Progress noted that it has experienced prior security incidents, including the 2023 breach of its MOVEit Transfer product that was exploited in widespread ransomware attacks and a critical vulnerability reported in MOVEit Automation in April 2026 that caused further disruptions. These historical events were mentioned only as contextual background and were not linked to the ShareFile Storage Zones Controller incident. The narrative concludes with the confirmation that the service was operational again after the patch deployment and that no customer data compromise was identified based on the information available at that time.
Sources
Sources available to members: 1 source.