Progress Software Disables ShareFile On‑Prem Servers Amid Credible Threat Targeting SZC Vulnerabilities (CVE‑2026‑2699, CVE‑2026‑2701)
What Happened — Progress Software identified a credible external threat aimed at the on‑premises ShareFile Storage Zone Controllers (SZC). The company temporarily disabled affected ShareFile accounts and instructed customers to shut down the SZC servers while it investigates. The threat is believed to involve chaining two known CVEs (CVE‑2026‑2699 and CVE‑2026‑2701) that could allow pre‑authentication remote code execution on unpatched deployments.
Why It Matters for Compliance & Audit Readiness
- This scenario exemplifies a control‑gap where on‑prem components are not continuously monitored for patch status, a key SOC 2 Control CC6.1 (System Operations) requirement.
- Demonstrating real‑time evidence that vulnerable assets are identified, patched, or isolated satisfies the “continuous monitoring” principle of SOC 2 and provides audit‑ready documentation.
- Leveraging Verisq’s Control Mapping capability lets you map the SZC patch‑management gap to specific SOC 2 controls and automatically collect evidence for auditors.
Who Is Affected — Enterprises across technology, financial services, and regulated sectors that deploy ShareFile on‑premises for file sharing and collaboration.
Recommended Actions
- Inventory all on‑prem SZC instances and verify patch levels against CVE‑2026‑2699/2701.
- Map the patch‑management gap to SOC 2 CC6.1 and CC7.1 (Change Management) controls in your compliance framework.
- Enable continuous evidence collection for configuration and patch status to create a defensible audit trail.
- Document the temporary shutdown and restoration steps as part of incident‑response evidence.
Source: Help Net Security
Technical Notes — The alleged attack chain links CVE‑2026‑2699 (pre‑auth RCE via input validation flaw) and CVE‑2026‑2701 (privilege‑escalation bug) on unpatched SZC deployments. No unauthorized data access has been confirmed. Source: same as above