Progress Software Urges Businesses to Immediately Shut Down ShareFile Storage Zone Controller Servers Over Credible External Threat
Progress Software has taken the unusual step of asking customers to immediately shut down servers running ShareFile Storage Zone Controller after detecting a credible external threat, underscoring the severity of the situation.
Corporate storage systems are rarely powered down except in cases of serious risk, yet the company has now instructed organizations to manually disable these controllers as an extra layer of protection while it investigates.
Progress Software has temporarily blocked ShareFile accounts that rely on Storage Zone Controller and launched an internal review. These controllers allow organizations to keep data within their own infrastructure or with a third-party provider, giving them full control over storage management rather than depending exclusively on cloud-hosted options.
The company has not revealed the nature of the threat or provided any timeline for lifting the restrictions. At the time of the notification, Progress Software stated it had found no signs of unauthorized access to ShareFile accounts or customer data.
Possible Connection to Recently Patched Vulnerabilities
Some users have suggested the incident may be related to two critical vulnerabilities patched in March: CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1). Although no official confirmation exists, the combination of these flaws could allow attackers to change controller settings without authentication, upload malicious files, and execute commands on the server.
While the investigation continues, Progress Software recommends that customers manually power off any servers hosting Storage Zone Controller. The company views this shutdown as an additional safeguard until more details become available.
Related articles
WatchGuard Fireware OS Affected by 15 Vulnerabilities Including Critical CVE-2026-86131
WatchGuard Technologies disclosed 15 vulnerabilities in Fireware OS, the operating system powering its UTM appliances. The advisories were published between September 29 and 30, 2026, covering issues that range from remote code execution and authorization bypass to file disclosure and denial of service. Impact varies by deployment, yet none of the flaws had been observed in active exploitation at disclosure time. The most severe finding, CVE-2026-86131 in BOVPN Over TLS, received a CVSS v4.0 base score of 9.2 and Critical rating. This code-injection flaw in client configuration handling allows an attacker who controls the VPN server to execute arbitrary commands with root privileges on the connecting Firebox device. The remaining vulnerabilities affect multiple components and are tracked under separate CVE identifiers listed in the official advisories.
Rust Researcher Builds AI Pipeline to Test 900 Vulnerability Hypotheses Across Crates and Linux Kernel
Sergey Gordeychik developed the rust-in-peace research harness that combines multiple LLM agents, traditional SAST tools, and dynamic verification to hunt for memory-safety, logic, and API misuse issues in Rust code. The system generates independent hypotheses, attempts to refute them with separate agents, then validates survivors through fuzzing, protocol tests, or container execution. Starting from the Damn Vulnerable Rust Application, the pipeline was expanded to popular crates including x509-parser, h2, and lopdf, ultimately producing a Linux kernel patch. Experiments showed that three parallel analysis passes yielded 20 confirmed findings after triage, with nine appearing in all passes. The work also highlighted how models can produce convincing but false positives when context such as dependency checks or call order is missing. Gordeychik presented the approach at ZeroNights under the title Rust in Peace: How to Raise Your Own Pet Mythos.
Critical Zero-Day Vulnerability in FortiMail Allows Unauthenticated File Writes
Fortinet disclosed a critical zero-day vulnerability in its FortiMail email security product that is already being exploited in attacks. The flaw, tracked as CVE-2026-104286, affects the graphical user interface component and stems from improper sanitization of path traversal and NULL byte sequences. Attackers can craft malicious HTTP requests to write arbitrary files to the system without authentication. The vulnerability received a CVSS v3.1 base score of 9.8, classifying it as Critical. Fortinet discovered the issue internally but has also received reports of active exploitation. Planned patches include FortiMail 8.0.2, 7.6.7, and 7.4.9, while users on the 7.2 branch are advised to migrate to 7.4 or later.
Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It
A detailed investigation reveals that Android VPN clients suffer from two distinct server address leaks when split tunneling is enabled. The first leak, tied to an unprotected local SOCKS proxy on 127.0.0.1, was quickly mitigated by most Xray and sing-box based clients through random ports and passwords. The second, more persistent leak allows excluded applications to bind sockets directly to the tun0 interface and discover the VPN server IP without root or special permissions. Only TeapodStream and OlConnect implemented owner-UID checks using ConnectivityManager.getConnectionOwnerUid, yet both initially mishandled the INVALID_UID response returned for excluded apps. AmneziaVPN has unmerged pull requests that correctly reject unknown owners, while sing-box offers a manual package_name_regex rule. v2rayNG closed the report as not planned, and major clients including WireGuard for Android, Mullvad, Proton VPN and others have issued no statements.