Progress Software Tells ShareFile Customers to Shut Down Their Servers
Progress Software has ordered customers running ShareFile's Storage Zone Controller offline, according to The Hacker News. The company says it is responding to a "credible external security threat" and has temporarily disabled access to affected accounts while working with outside security experts.
The Storage Zone Controller is a Windows server companies run on their own premises, letting files stay on internal storage while ShareFile's cloud handles sharing and access. It typically sits at the network's edge, reachable from the internet — which makes it useful and, as it turns out, a standing target.
The shutdown order rather than a patch tells you what you need to know. When a fix exists, companies issue it. Ordering servers fully offline usually means no fix exists yet.
Progress says it has found no evidence of unauthorised access to accounts or data. That is careful wording: it says nothing about what may have happened on the controllers themselves.
This is not the first time this software has been in the crosshairs. In 2023, when the product still belonged to Citrix, attackers exploited a critical unauthenticated flaw (CVE-2023-24489) in the same component, and CISA flagged it as actively exploited.
What to do:
- Keep affected controllers offline until Progress issues clear guidance.
- Confirm you are on version 5.12.4 or later on the 5.x line, or any 6.x release. This closes earlier known flaws but does not authorise a restart.
- If your controller was internet-facing, treat it as a potential incident. Preserve logs, check for unfamiliar files in web and storage folders, and begin your incident-response process.
Sources

