{"id":582040,"date":"2026-07-12T16:23:13","date_gmt":"2026-07-12T16:23:13","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/582040\/"},"modified":"2026-07-12T16:23:13","modified_gmt":"2026-07-12T16:23:13","slug":"progress-told-sharefile-customers-to-pull-the-plug-on-their-servers-heres-what-we-know","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/582040\/","title":{"rendered":"Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here&#8217;s What We Know."},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here\u2019s What We Know.\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> July 12, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/1783873392_691_image-35.png\" alt=\"\"\/><\/p>\n<p>Progress urged ShareFile Storage Zone customers to shut down internet-facing servers immediately over a credible security threat under investigation.<\/p>\n<p class=\"wp-block-paragraph\">Progress Software sent an urgent email to ShareFile customers the evening of July 10 with a subject line that left no room for ambiguity: \u201cService Disruption. Immediate Action Required.\u201d The company told customers running Storage Zone Controllers to shut down their Windows servers immediately, citing what it called a \u201ccredible external security threat.\u201d <\/p>\n<p class=\"wp-block-paragraph\">The email became public when a system administrator <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/1usohco\/psa_shutdown_your_sharefile_storage_zone\/\" rel=\"nofollow noopener\" target=\"_blank\">posted it to Reddit\u2019s r\/sysadmin<\/a> a few hours later.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/07\/image-35.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"596\" height=\"510\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/07\/1783873393_586_image-35.png\" alt=\"\" class=\"wp-image-195198\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Storage Zone Controllers are the on-premises component of ShareFile\u2019s hybrid deployment model. Organizations that use them keep their files on their own infrastructure while ShareFile\u2019s cloud handles authentication, user management, and collaboration. Because the controller sits between the cloud platform and company-managed storage, handling every file upload and download, it typically lives at the network\u2019s edge with internet exposure. That\u2019s what makes it useful, and that\u2019s what makes it a target.<\/p>\n<p class=\"wp-block-paragraph\">Progress confirmed it\u2019s responding to a credible external security threat and <a href=\"https:\/\/thehackernews.com\/2026\/07\/urgent-progress-tells-sharefile.html\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> it took the access-disabling step out of an \u201cabundance of caution\u201d while working with internal and external security experts. <\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have reason to believe there is a credible external security threat targeting Progress Software\u2019s ShareFile Storage Zone Controllers. Currently, we have no indication of unauthorized access to any Progress ShareFile accounts or data. As a precaution, we have temporarily disabled access to ShareFile accounts using the Storage Zone Controllers, including yours.\u201d reads the letter. \u201cIMMEDIATE ACTION REQUIRED: You must manually shut down the server hosting your Storage Zone Controllers. This is a critical additional step to ensure the safety of your data.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Cutting off cloud-side access apparently wasn\u2019t considered sufficient on its own. Progress also instructed customers to manually shut down the physical Windows servers hosting their Storage Zone Controllers, calling it a critical additional step. The ShareFile status page confirmed the disruption at 12:12 p.m. EDT, listing Storage Zone Controller customers as not operational with an active investigation underway. Only the hybrid Storage Zone Controller deployment is affected. Standard cloud-only ShareFile accounts are not impacted.<\/p>\n<p class=\"wp-block-paragraph\">Progress hasn\u2019t disclosed details about the threat, who is behind it, whether any controller has been compromised, or when customers can safely restart. It is also unknown which version is potentially impacted by the current threat. That\u2019s a narrow information window for organizations that may be sitting on sensitive files and need to assess their exposure.<\/p>\n<p class=\"wp-block-paragraph\">ShareFile\u2019s Storage Zone Controllers have a documented history with exactly this kind of threat. In 2023, while the product still belonged to Citrix, attackers exploited an unauthenticated remote code execution flaw, <a href=\"https:\/\/securityaffairs.com\/148981\/hacking\/citrix-sharefile-cve-2023-24489-flaws-attacks.html\" type=\"post\" id=\"148981\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2023-24489<\/a>, in the Storage Zones Controller. CISA <a href=\"https:\/\/securityaffairs.com\/149578\/hacking\/citrix-sharefile-known-exploited-vulnerabilities-catalog.html\" type=\"post\" id=\"149578\" rel=\"nofollow noopener\" target=\"_blank\">flagged<\/a> it as actively exploited, and Citrix cut unpatched controllers off from the ShareFile cloud, which is precisely the same access block Progress has now imposed. Progress acquired ShareFile in 2024.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Follow me on Twitter:\u00a0<\/strong><a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>@securityaffairs<\/strong><\/a><strong>\u00a0and\u00a0<\/strong><a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Facebook<\/strong><\/a><strong>\u00a0and\u00a0<\/strong><a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Mastodon<\/strong><\/a><strong\/><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\"><strong>Pierluigi\u00a0Paganini<\/strong><\/a><strong\/><\/p>\n<p class=\"wp-block-paragraph\"><strong>(<\/strong><a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\"><strong>SecurityAffairs<\/strong><\/a><strong>\u00a0\u2013\u00a0hacking,\u00a0Progress Told ShareFile)<\/strong><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here\u2019s What We Know. Pierluigi Paganini July&hellip;\n","protected":false},"author":2,"featured_media":582041,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[18,7243,21708,19,41883,17,246931,246932,12765,246933,246934,247365,82],"class_list":["post-582040","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-eire","tag-hacking","tag-hacking-news","tag-ie","tag-information-security-news","tag-ireland","tag-it-information-security","tag-pierluigi-paganini","tag-progress","tag-security-affairs","tag-security-news","tag-sharefile-storage-zone","tag-technology"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/582040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=582040"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/582040\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/582041"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=582040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=582040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=582040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}