ShareFile zero-day: your vendor told you to unplug
Progress ordered ShareFile customers to power off Storage Zone Controllers, then confirmed a path traversal zero-day. Patches shipped before the CVE did. Here's the lesson.
Progress told ShareFile customers to shut down their Storage Zone Controllers over a "credible external security threat," disabled the affected accounts, and only confirmed the underlying zero-day days later. The patch shipped before the CVE was even published. If your file-sharing runs on ShareFile, this is a patch-now item — and if it doesn't, it's still the cleanest recent example of a failure mode most small businesses have never planned for.
What actually happened
Progress confirmed a high-severity path traversal flaw affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, and shipped fixed builds 5.12.5 and 6.0.2. Per BleepingComputer, an authenticated administrative user could read arbitrary files reachable by the application's service account, write attacker-controlled content into arbitrary directories, or enumerate the server filesystem. Progress says it has no indication of unauthorized access to any customer account or data.
The sequence is the interesting part. Help Net Security reported the emergency shutdown instruction on July 13; the vulnerability confirmation and patches followed. Progress reserved a CVE but held publication for roughly two weeks — deliberately, to give customers a head start before the details are public.
Storage Zone Controllers are the customer-managed Windows servers that keep your files on-prem while the ShareFile cloud handles the front end. Which means the box holding your documents is the box you patch.
Why an emergency shutdown matters for your business
Nobody's runbook says "power off the file server today, indefinitely, and we'll tell you why later." But that was the instruction, and it was the right one. The question is whether your business could have followed it.
Three things to know before it's you. One: which vendors can hand you an outage you didn't choose — and how do they reach you? A support-portal banner nobody reads is not a notification channel. Two: what breaks if a given system goes dark for 48 hours, and what's the manual path? Three: who applies the patch on a self-managed box on a Saturday, and how fast?
Also note what this episode does to CVE-driven security. Progress patched before publishing. If your process starts when a CVE lands in a feed, you were days behind on this one. Vendor advisories are the leading indicator; the CVE is the receipt.
Key takeaways
- Progress told ShareFile customers to power off Storage Zone Controllers on July 13 over a credible threat, then confirmed a path traversal zero-day in all 5.x and 6.x versions
- Fixed builds are 5.12.5 and 6.0.2 — patch and restore, don't wait for the CVE, which Progress deliberately delayed
- Progress reports no evidence of unauthorized access to customer accounts or data
- Self-managed appliances mean vendor-initiated downtime is your operational problem: know the notification path, the blast radius, and who patches on a weekend
Not sure what goes dark if a vendor says "unplug it"? We map the systems your business actually depends on and build the fallbacks. See what we build.
Sources: BleepingComputer, Help Net Security.
- #sharefile
- #zero-day
- #patch-management
- #vendor-risk
- #security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it