watchTowr finds pre-auth RCE chain in Progress ShareFile
watchTowr published an analysis of a pre-authentication remote code execution chain in Progress ShareFile, tracked as CVE-2026-2699 and CVE-2026-2701. Around the same time, Progress patched a critical authentication bypass in MOVEit Automation, CVE-2026-4670. Both flaws sit in the authentication layer rather than file handling logic.
- ShareFile: pre-auth RCE chain tracked as CVE-2026-2699 and CVE-2026-2701
- MOVEit Automation: critical authentication bypass CVE-2026-4670
- Both flaws hit the authentication layer, not file handling logic
- Experts urge MFT inventory, patching and key rotation
Read next
Security