PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16138 Progress CVE debrief

Unsafe deserialization of untrusted file metadata in Progress ShareFile Storage Zones Controller v5.12.5 and below can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. This vulnerability, with a CVSS score of 8, indicates high severity and requires immediate attention. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The vulnerability class involves arbitrary code execution due to unsafe deserialization. Likely operational impact includes potential system compromise. Source-confidence limits are based on official CVE and vendor advisory information. Review context suggests applying patches, restricting access, and monitoring for suspicious activity.

Vendor
Progress
Product
ShareFile Storage Zones Controller
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-02
Advisory published
2026-08-17
Advisory updated
2026-09-02

Who should care

Administrators and users of Progress ShareFile Storage Zones Controller versions 5.12.5 and below should be aware of this vulnerability and take necessary actions to mitigate it. This includes applying patches, restricting access, and monitoring for suspicious activity.

Technical summary

The vulnerability in Progress ShareFile Storage Zones Controller versions 5.12.5 and below allows for arbitrary code execution due to unsafe deserialization of untrusted file metadata. A user with write access to a Network share can exploit this vulnerability. The CVSS score is 8, indicating high severity.

Defensive priority

High-priority defensive actions are required to address the vulnerability in Progress ShareFile Storage Zones Controller. The vulnerability allows for arbitrary code execution on the Storage Zones Controller host by a user with write access to a Network share due to unsafe deserialization of untrusted file metadata.

Recommended defensive actions

  • Apply the vendor-provided patch for Progress ShareFile Storage Zones Controller version 5.12.6 or later.
  • Restrict write access to Network shares for users who do not require it.
  • Monitor for suspicious activity on the Storage Zones Controller host.
  • Perform regular inventory checks to ensure all instances of Progress ShareFile Storage Zones Controller are updated.
  • Consider implementing compensating controls, such as additional monitoring or access restrictions.

Evidence notes

The CVE-2026-16138 record indicates that Progress ShareFile Storage Zones Controller versions 5.12.5 and below are vulnerable to unsafe deserialization of untrusted file metadata. A user with write access to a Network share can exploit this to execute arbitrary code on the Storage Zones Controller host. The CVSS score is 8, indicating a high severity vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16138 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16138

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16138 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16138

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.