← All CVEs

CVE-2026-2699

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

9.8
CVSS
59.5%
EPSS (exploit prob.)
99th
EPSS percentile
2026-04-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-284CWE-698

Affected products

VendorProductAffected versions
progresssharefile_storage_zones_controller>= 5.0.0, < 5.12.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-2699