Progress ShareFile Storage Zone Controllers Taken Offline — No Patch, No CVE, Credible Zero-Day Threat Active
Progress Software ordered all on-premises ShareFile Storage Zone Controller customers to immediately shut down their Windows servers on July 10, citing a 'credible external security threat' — with no patch, no CVE, and no technical disclosure issued. The directive to fully power off rather than patch strongly implies an unmitigated vulnerability, echoing the 2023 MOVEit and Citrix ShareFile CVE-2023-24489 mass-exploitation playbooks. Internet-facing Storage Zone Controllers — of which Shadowserver identified ~784 exposed instances at the time of April 2026 CVE disclosures — should be treated as potentially implanted until Progress provides clean indicators and a verified remediation path.
The directive to fully power off rather than patch strongly implies an unmitigated vulnerability, echoing the 2023 MOVEit and Citrix ShareFile CVE-2023-24489 mass-exploitation playbooks.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.