Skip to content
Flash Briefing high FinanceHealthcareCritical InfrastructureCommunications

Progress Orders ShareFile Storage Zone Controllers Offline Over Active Security Threat

Progress Software has instructed all customers running ShareFile Storage Zone Controllers to take those systems fully offline, citing a credible external security threat. The order, confirmed by Progress to The Hacker News on July 10, 2026, applies to the self-hosted Windows servers that sit between an organisation’s on-premises storage and the ShareFile cloud service.

Progress has no fix to offer. That detail matters more than any other in this advisory.

What Happened

The incident became public when a customer posted Progress’s shutdown email to Reddit’s r/sysadmin on July 10. Progress confirmed the disruption on its status page, describing Storage Zone Controller deployments as “not operational” with an incident under investigation. The company says it has found no evidence of unauthorised access to accounts or data, but that carefully worded statement does not address what may have happened on the controllers themselves.

Progress says it is working with internal and external security experts and notified customers after learning of the threat. It has not said publicly what the threat is, who reported it, or how long the investigation is expected to take.

Only the Storage Zone Controller component is in scope. Standard cloud-only ShareFile accounts, where Progress holds the storage, are not affected.

Why the Shutdown Order Is Significant

When a vendor responds to a security threat by ordering customers to shut down their infrastructure rather than patch it, one of two things is usually happening: either no patch exists because the flaw is newly discovered, or the threat is not a software vulnerability — it could be compromised keys, a supply-chain problem, or an issue on Progress’s own infrastructure.

The Storage Zone Controller runs at the network perimeter with internet exposure by design. That makes it both operationally useful and an attractive target for threat actors looking for a pathway into the organisations that use it.

ShareFile is a managed file transfer (MFT) platform widely deployed in financial services, healthcare, legal, and professional services sectors for regulated document exchange. The finance and healthcare sectors rely on it heavily for compliant client file sharing. Any active exploitation of this infrastructure would carry significant data exposure risk, particularly for organisations sharing sensitive financial records or patient data.

Historical Pattern

This is not the first time ShareFile’s Storage Zones Controller has been targeted.

In 2023, when the product belonged to Citrix, attackers exploited CVE-2023-24489, a critical unauthenticated flaw in the same component. CISA added it to the Known Exploited Vulnerabilities catalogue, and Citrix responded by blocking unpatched controllers from connecting to the ShareFile cloud. The response pattern is nearly identical to what Progress is doing now.

Progress acquired ShareFile from Citrix in 2024. Progress itself entered the threat intelligence spotlight in 2023 when Clop exploited a zero-day in MOVEit Transfer (another Progress MFT product), resulting in data theft at more than 2,700 organisations globally and one of the most extensive supply-chain data breach campaigns on record.

Two critical vulnerabilities in the Storage Zones Controller disclosed by watchTowr in April 2026, and patched by Progress in March, have not been officially connected to the current threat. Neither has been reported as actively exploited. Progress has not stated whether these flaws are relevant to its current investigation.

If you run a Storage Zone Controller:

Follow Progress’s order and take the controller offline immediately. Do not restart it until Progress provides explicit guidance confirming what the threat is and how to address it.

Ensure your controller version is current (5.12.4 or later on the 5.x branch, or any 6.x release) to close the April-patched vulnerabilities, but do not treat version currency as clearance to bring the controller back online.

Treat internet-reachable controllers as potentially compromised. Preserve logs, activate your incident response process, and conduct a targeted review for anomalous .aspx files in web directories and unexpected files in storage paths.

If the controller was internet-facing during the period of uncertainty, escalate to your security operations team for forensic review before returning it to service.

For security and risk teams:

Identify whether ShareFile Storage Zone Controllers are present in your supplier ecosystem, including managed service providers and professional services firms that handle sensitive documents on your behalf. Third-party exposure through this class of MFT vulnerability is a documented risk from the MOVEit and GoAnywhere campaigns.