peter bassill · operator
$ cve CVE-2026-2699 JSON

CVE-2026-2699

9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.18% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2026-04-02
Last modified2026-06-17

Affected (1)

VendorProduct
progresssharefile storage zones controller

References

→ the Explorer  ·  watch your stack  ·  NVD