Progress ShareFile Storage Zone Controller shutdown: security threat

Progress orders emergency shutdown of ShareFile Storage Zone Controllers

Progress Software has ordered all customers running on-premises ShareFile Storage Zone Controllers (SZC) to immediately shut down their servers after identifying a credible external security threat. This urgent move affects organisations relying on ShareFile’s hybrid deployment, highlighting a significant risk in the file-sharing landscape.

Emergency ShareFile Storage Zone Controller shutdown: what happened

On 10 July 2026, Progress Software sent an emergency directive to all customers operating ShareFile Storage Zone Controllers on-premises. The message, distributed via email and reinforced by direct phone calls, instructed organisations to immediately power down their Windows servers hosting the SZC application. Progress also took the additional step of disabling cloud access for ShareFile accounts linked to these on-premises components, but made it clear that this precaution was not enough: servers themselves must be shut down to secure data.

This drastic measure followed the discovery of a “credible external security threat” targeting the Storage Zone Controller component. The company described the move as being made “out of an abundance of caution” and stated it was working with both internal and external cybersecurity experts to assess the threat’s nature and scope. Progress has not released technical details regarding the vulnerability or attack vector, and as of mid-July 2026, has not identified any active exploitation or unauthorised access to customer data.

  • 10 July 2026: Progress issues a security alert requiring all on-prem SZC servers to be shut down immediately. Cloud access for hybrid accounts is disabled as a precaution.
  • 11–12 July 2026: Progress confirms no observed exploitation or data compromise, but insists SZC servers remain offline. Limited cloud functionality is restored for unaffected features.
  • 13 July 2026: The shutdown remains in effect, with no patch or workaround provided. Progress has not disclosed the specific vulnerability or affected versions, fuelling speculation across the IT and security community.

Throughout this period, Progress has maintained a tight information policy, declining to answer media questions or provide indicators of compromise. The company has promised further updates as the investigation continues.

Which ShareFile products and versions are affected?

The emergency shutdown applies to the on-premises component of Progress ShareFile known as the Storage Zone Controller. This software is typically deployed as a Windows Server IIS web application, allowing organisations to store files locally while still integrating with ShareFile’s cloud-based authentication and management features. Only self-hosted Storage Zone Controllers are impacted; standard cloud-only ShareFile accounts are unaffected.

Progress has not specified which versions or builds of the Storage Zone Controller are at risk. However, the blanket shutdown order for all on-prem deployments strongly suggests that all supported versions, including the latest releases, may be vulnerable. Earlier in 2026, Progress patched critical pre-authentication remote code execution (RCE) vulnerabilities in SZC v5.x, urging customers to upgrade to v5.12.4 or v6.0. During this July 2026 incident, even fully patched servers are under the shutdown directive, implying that the threat could affect a common component across all versions.

  • Affected product: Progress ShareFile Storage Zone Controller (on-premises)
  • Affected versions: All supported versions (including v5.x and possibly v6.x) are assumed at risk
  • Deployment model: Only self-hosted, on-premises Storage Zone Controllers are impacted

Organisations with any version of the Storage Zone Controller on Windows should consider their system potentially vulnerable and keep it offline until further notice from Progress.

How the suspected attack or vulnerability works

While technical details remain undisclosed, several factors point to a severe software flaw. The Storage Zone Controller is an internet-facing web application that facilitates secure file transfers and integrates with ShareFile’s cloud platform. The urgency and breadth of Progress’s response suggest a likely zero-day vulnerability, potentially allowing pre-authentication remote code execution. This would mean an attacker could exploit the flaw remotely—without valid credentials—to gain full control of the SZC server.

In previous incidents earlier in 2026, ShareFile Storage Zone Controller v5.x was found vulnerable to logic flaws and arbitrary file upload bugs. When chained, these could allow an attacker to bypass authentication and upload a malicious file, leading to complete system compromise. Although Progress has not confirmed a direct link between those vulnerabilities and the current threat, the context implies a similar level of risk.

  • The vulnerability is likely remotely exploitable, with no patch or configuration workaround available at this time.
  • Progress’s order to shut down servers—not merely apply a patch or restrict access—suggests the risk is imminent and serious.
  • There is no evidence, as of 13 July 2026, that any attackers have breached customer data or accounts, but the company is acting as if exploitation could happen at any moment.

Progress has not published indicators of compromise, proof-of-concept exploits, or attribution to any specific threat actor. Speculation in the IT community centres on the possibility of an unauthenticated RCE exploit, but this is not confirmed.

Current status and industry response

As of mid-July 2026, the Storage Zone Controller outage is ongoing. Customers remain unable to use their on-premises ShareFile storage components, and no fix, mitigation, or safe version has been identified. Progress has assured customers that no data compromise has been observed so far, but the lack of technical detail has fuelled anxiety and speculation among IT and security professionals. The unusual step of a full server shutdown, rather than a patch or configuration change, highlights the seriousness of the risk and the absence of an immediate solution.

No threat actor has been named, and there are no reports of public proof-of-concept exploit code. Until Progress completes its investigation and issues new guidance or a software update, organisations are advised to keep their Storage Zone Controllers offline and monitor official communications closely.

Why this ShareFile Storage Zone Controller threat matters

This incident underscores the risks of hybrid cloud deployments and the exposure of internet-facing enterprise applications. The lack of technical details and the urgency of the shutdown directive make this a high-impact event for any organisation relying on ShareFile’s on-premises capabilities. Given Progress’s recent history with high-profile vulnerabilities, the industry is watching closely for updates.

What should organisations do now?

  • Keep all on-premises ShareFile Storage Zone Controllers powered off until Progress provides a patch or further instructions.
  • Monitor Progress’s official channels for updates and incident status changes.
  • Review internal documentation of hybrid ShareFile deployments and prepare contingency plans for extended downtime if required.

Originally reported by theregister.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call