News & Insights

Progress Software Advises ShareFile Customers to Shut Down Self-Managed Storage Zone Controllers Due to Credible Security Threats

What happened?

Data Breach Today released an article regarding Progress Software issuing a security alert urging organizations that use self-managed ShareFile Storage Zone Controllers to immediately shut down those systems due to a credible external security threat.

The warning coincides with reports from security researchers who detected active attempts to exploit a previously patched authentication bypass vulnerability in ShareFile Storage Zone Controller software. While the vulnerability was addressed in April of this year, attackers may have been targeting systems that remained unpatched or exposed.

Progress stated that it currently has no evidence of unauthorized access to customer accounts or data but has taken precautionary measures by temporarily disabling access through potentially affected Storage Zone Controllers and instructing administrators to power down their systems while the issue is investigated. On July 14, Progress released updates to address the vulnerability and urged organizations to upgrade their Storage Zone Controllers to the latest version. After upgrading, access to Storage Zone Controllers should be restored. Progress has marked the issue as “resolved” on its ShareFile status page and has published a support article outlining the resolution steps.

What does this mean for me?

Progress has not yet disclosed the nature of the threat. Organizations using customer-managed ShareFile Storage Zone Controllers should follow all recommended mitigation steps to upgrade their Storage Zone Controllers to the latest versions and continue monitoring Progress security. While Fairview does not use self-managed Storage Zone Controllers in ShareFile and is not impacted by this issue, we are sharing this information to raise awareness of the recently disclosed security threat, as it may impact organizations that do.