¡¾Îó²îͨ¸æ¡¿Progress ShareFile Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-2701)

Ðû²¼Ê±¼ä 2026-04-10

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Progress ShareFile Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2026-2701

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2026-4-10

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Progress ShareFileÊÇÒ»¿îÆóÒµ¼¶Çå¾²Îļþ´«ÊäÓëЭ×÷ƽ̨£¬£¬£¬£¬Ö§³ÖÎļþ¹²Ïí¡¢Êý¾ÝÍøÂç¡¢µç×ÓÊðÃû¼°Ê¹ÃüÖÎÀíµÈ¹¦Ð§¡£ ¡£¡£¡£ÆäStorage Zone Controller×é¼þÔÊÐíÆóÒµÔÚÍâµØ»ò×Ô½ç˵´æ´¢ÇéÐÎÖÐÍйÜÊý¾Ý£¬£¬£¬£¬Í¬Ê±Í¨¹ýShareFile SaaSƽ̨¾ÙÐÐͳһ»á¼û¿ØÖÆÓëÖÎÀí£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ¶ÔÊý¾ÝÖ÷ȨºÍºÏ¹æÒªÇó½Ï¸ßµÄ×éÖ¯¡£ ¡£¡£¡£


2026Äê4ÔÂ8ÈÕ£¬£¬£¬£¬¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Progress ShareFile±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-2701£©£¬£¬£¬£¬Í¬Ê±»¹±£´æÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î£¨CVE-2026-2699£©£¬£¬£¬£¬¶þÕß¿É×éºÏʹÓÃÐγÉδÊÚȨԶ³Ì´úÂëÖ´Ðй¥»÷Á´¡£ ¡£¡£¡£ÆäÖУ¬£¬£¬£¬CVE-2026-2699Ô´ÓÚASP.NETÓ¦ÓùýʧʹÓÃResponse.Redirect(..., false)£¬£¬£¬£¬ÔÚÖØ¶¨ÏòºóδÖÕÖ¹Ò³ÃæÖ´ÐУ¬£¬£¬£¬µ¼ÖÂδÈÏÖ¤Óû§¿ÉÈÆ¹ýÉí·ÝÑéÖ¤»á¼ûºǫ́¹¦Ð§£»£»£»£»£»£»ÔÚ´Ë»ù´¡ÉÏ£¬£¬£¬£¬CVE-2026-2701ÓÉÓÚϵͳÔڴ洢·¾¶ÉèÖü°ÎļþÉÏ´«½âѹÂß¼­ÖÐȱ·¦ÓÐÓÃÇå¾²ÏÞÖÆ£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß½«ÎļþдÈëWebĿ¼²¢Ö´ÐС£ ¡£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÈÏÖ¤¼´¿Éͨ¹ý½á¹¹ÇëÇóÐÞ¸ÄϵͳÉèÖ㬣¬£¬£¬²¢Á¬ÏµÎļþÉÏ´«Óë½âѹ¹¦Ð§Ð´Èë¶ñÒâASPX WebShell£¬£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡¢ÏµÍ³ÍêȫʧÏݼ°ºáÏòÉøÍ¸µÈÑÏÖØÇ徲Σº¦¡£ ¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Storage Zone Controller 5.x <= 5.12.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£ ¡£¡£¡£
Storage Zone Controller >= 5.12.4


ÏÂÔØÁ´½Ó£ºhttps://docs.sharefile.com/en-us/storage-zones-controller/5-0/upgrade/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£ ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£ ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£ ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£ ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£ ¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£ ¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.cve.org/CVERecord?id=CVE-2026-2701/
https://www.cve.org/CVERecord?id=CVE-2026-2699
https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/
https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26