What is CVE-2026-16138?
CVE-2026-16138 is an unsafe deserialization vulnerability in Progress ShareFile Storage Zones Controller v5.12.5 and below. It allows a user with write access to a network share to achieve arbitrary code execution on the Storage Zones Controller host. Updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-16138, Progress ShareFile Storage Zones Controller proqramının 5.12.5 və daha əvvəlki versiyalarında etibarsız fayl metadata-sının unsafe deserialization zəifliyidir. Bu, şəbəkə paylaşımına yazma icazəsi olan istifadəçiyə Storage Zones Controller hostunda ixtiyari kod icra etməyə imkan verə bilər. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Progress
FAQ2
Which software product is affected by CVE-2026-16138?
This vulnerability affects Progress ShareFile Storage Zones Controller versions 5.12.5 and below.
What privileges does an attacker need to exploit CVE-2026-16138?
The attacker must be a user with write access to a network share.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.