PatchSiren cyber security CVE debrief
CVE-2026-16138 Progress CVE debrief
Unsafe deserialization of untrusted file metadata in Progress ShareFile Storage Zones Controller v5.12.5 and below can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. This vulnerability, with a CVSS score of 8, indicates high severity and requires immediate attention. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The vulnerability class involves arbitrary code execution due to unsafe deserialization. Likely operational impact includes potential system compromise. Source-confidence limits are based on official CVE and vendor advisory information. Review context suggests applying patches, restricting access, and monitoring for suspicious activity.
- Vendor
- Progress
- Product
- ShareFile Storage Zones Controller
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-02
Who should care
Administrators and users of Progress ShareFile Storage Zones Controller versions 5.12.5 and below should be aware of this vulnerability and take necessary actions to mitigate it. This includes applying patches, restricting access, and monitoring for suspicious activity.
Technical summary
The vulnerability in Progress ShareFile Storage Zones Controller versions 5.12.5 and below allows for arbitrary code execution due to unsafe deserialization of untrusted file metadata. A user with write access to a Network share can exploit this vulnerability. The CVSS score is 8, indicating high severity.
Defensive priority
High-priority defensive actions are required to address the vulnerability in Progress ShareFile Storage Zones Controller. The vulnerability allows for arbitrary code execution on the Storage Zones Controller host by a user with write access to a Network share due to unsafe deserialization of untrusted file metadata.
Recommended defensive actions
- Apply the vendor-provided patch for Progress ShareFile Storage Zones Controller version 5.12.6 or later.
- Restrict write access to Network shares for users who do not require it.
- Monitor for suspicious activity on the Storage Zones Controller host.
- Perform regular inventory checks to ensure all instances of Progress ShareFile Storage Zones Controller are updated.
- Consider implementing compensating controls, such as additional monitoring or access restrictions.
Evidence notes
The CVE-2026-16138 record indicates that Progress ShareFile Storage Zones Controller versions 5.12.5 and below are vulnerable to unsafe deserialization of untrusted file metadata. A user with write access to a Network share can exploit this to execute arbitrary code on the Storage Zones Controller host. The CVSS score is 8, indicating a high severity vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.