CVE-2026-16138
Medium
Elevated severity or exploit probability.
CVSS base
8.0
HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.8%
55.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-502
Published 2026-08-17 · modified 2026-09-02
Description
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.