Progress Software tells ShareFile customers to physically shut down servers over unnamed threat

Progress Software emailed ShareFile customers on July 10 with an unusual instruction: physically shut down the Windows servers hosting their Storage Zone Controllers. The company says it identified a credible external security threat targeting the on-premises component of its enterprise file-sharing platform, though it has not disclosed what the threat is, who is behind it, or whether any exploit has actually been used against a customer.
The order became public after a customer posted Progress's email to Reddit's r/sysadmin. In it, Progress states it currently has no indication of unauthorized access to any ShareFile accounts or data, but is treating the threat as serious enough to require action beyond simply restricting cloud-side access: “You must manually shut down the server hosting your Storage Zone Controllers. This is a critical additional step to ensure the safety of your data.”
What's actually affected
Storage Zone Controllers are self-hosted Windows servers that let ShareFile customers keep files on their own storage infrastructure while still using ShareFile's cloud platform for authentication, sharing links, and user management — a common setup for organizations with data residency or compliance requirements that rule out fully cloud-hosted storage. Standard cloud-only ShareFile accounts, without a self-hosted Storage Zone Controller, are not affected by this specific advisory.
Not the same as April's disclosed vulnerabilities
This incident is distinct from two critical vulnerabilities in the Storage Zone Controller that security researchers at watchTowr Labs disclosed in April 2026: CVE-2026-2699, an authentication bypass scoring 9.8 on the CVSS scale, and CVE-2026-2701, a remote code execution flaw scoring 9.1. Chained together, those bugs allowed an unauthenticated attacker to reach restricted configuration pages and upload a malicious webshell for full remote code execution — and Progress patched them at the time. Progress has not said whether this new threat is connected to that earlier vulnerability chain, an unpatched variant of it, or something else entirely.
What happens next
As of the most recent update, Progress had not published a patch or a timeline for one, and the ShareFile status page continued to show Storage Zone Controller services as non-operational. The company said it was working with outside security experts and promised customers a further update within 24 hours of its initial notice — a commitment that, as of this writing, has not been followed by a public disclosure of the threat's nature.
For enterprise IT teams, the practical takeaway is blunt: an advisory that asks customers to physically power down production servers, rather than simply patch or restrict access, signals a threat Progress considers too dangerous to leave running even briefly while a fix is prepared.
As reported by BleepingComputer, Progress has not yet disclosed further technical details of the threat.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source