CVE-2026-16138
8.0Progress · ShareFile Storage Zones Controller
Progress ShareFile Storage Zones Controller contains a deserialization of untrusted data vulnerability that could lead to unauthorized system impact.
Executive summary
A deserialization vulnerability in Progress ShareFile Storage Zones Controller exposes systems to potential compromise through the processing of untrusted data.
Vulnerability
This vulnerability is a deserialization of untrusted data (CWE-502) flaw. The attack vector requires the attacker to have low privileges on an adjacent network, where they can exploit the controller to achieve high impact on confidentiality, integrity, and availability.
Business impact
Successful exploitation allows an attacker to execute arbitrary code or perform unauthorized actions within the context of the Storage Zones Controller. Given the CVSS score of 8.0, this represents a high risk to business operations, potentially leading to total system compromise and the exposure of sensitive data stored within the ShareFile environment.
Remediation
Immediate Action: Upgrade to ShareFile Storage Zones Controller version 5.12.6 or later to eliminate the vulnerable deserialization code path.
Proactive Monitoring: Inspect network traffic for unusual patterns directed at the Storage Zones Controller and review administrative access logs for unauthorized activity.
Compensating Controls: Implement network segmentation to restrict access to the controller to authorized personnel only, reducing the attack surface for adjacent network threats.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
The vulnerability poses a significant risk to the integrity of the ShareFile infrastructure. Administrators should prioritize the deployment of version 5.12.6, as patching is the only effective method to remediate this deserialization flaw.