← Back to BrewedIntel
otherlowCVE-2026-2699CVE-2026-2701

Apr 06, 2026 • Julian Tuin

CVE-2026-2699 & CVE-2026-2701: Progress ShareFile Storage Zones Controller Pre-Auth RCE Chain

On March 10, 2026, Progress ShareFile released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x,...

Source
Arctic Wolf Labs
Category
other
Severity
low

Summary

On March 10, 2026, Progress ShareFile released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and CVE-2026-2701. The first flaw arises from an authentication bypass due to improper redirect/session handling (Execution After Redirect) in /ConfigService/Admin.aspx that allows a remote unauthenticated threat actor to access restricted administrative ... CVE-2026-2699 & CVE-2026-2701: Progress ShareFile Storage Zones Controller Pre-Auth RCE Chain

Published Analysis

On March 10, 2026, Progress ShareFile released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and CVE-2026-2701. The first flaw arises from an authentication bypass due to improper redirect/session handling (Execution After Redirect) in /ConfigService/Admin.aspx that allows a remote unauthenticated threat actor to access restricted administrative ... CVE-2026-2699 & CVE-2026-2701: Progress ShareFile Storage Zones Controller Pre-Auth RCE Chain On March 10, 2026, Progress ShareFile released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and CVE-2026-2701. The first flaw arises from an authentication bypass due to improper redirect/session handling (Execution After Redirect) in /ConfigService/Admin.aspx that allows a remote unauthenticated threat actor to access restricted administrative ... CVE-2026-2699 & CVE-2026-2701: Progress ShareFile Storage Zones Controller Pre-Auth RCE Chain

Linked Entities

  • CVE-2026-2699
  • CVE-2026-2701