CVE-2026-16137
- EPSS 0.52%
- Veröffentlicht 17.08.2026 13:32:45
- Zuletzt bearbeitet 18.08.2026 04:16:43
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the...
- EPSS 0.26%
- Veröffentlicht 17.08.2026 13:32:01
- Zuletzt bearbeitet 18.08.2026 04:16:43
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
CVE-2026-16139
- EPSS 0.65%
- Veröffentlicht 17.08.2026 13:31:14
- Zuletzt bearbeitet 18.08.2026 04:16:44
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intende...
CVE-2026-15724
- EPSS 0.34%
- Veröffentlicht 21.07.2026 16:55:34
- Zuletzt bearbeitet 24.07.2026 05:16:38
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directorie...
CVE-2026-2701
- EPSS 56.67%
- Veröffentlicht 02.04.2026 13:04:38
- Zuletzt bearbeitet 21.04.2026 00:28:12
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-2699
- EPSS 58.39%
- Veröffentlicht 02.04.2026 13:04:00
- Zuletzt bearbeitet 21.04.2026 00:26:13
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.