Progress Software sent emergency guidance to ShareFile customers running on-premises Storage Zone Controllers, telling them to shut down their servers immediately after the company identified what it called a "credible external security threat." The warning applies to organizations that self-host ShareFile's file-sharing infrastructure rather than rely solely on cloud-managed services — a configuration common among healthcare organizations with data residency requirements or legacy integration needs.

What Progress disclosed

Progress described the threat as external and credible, without specifying whether it involves an unpatched vulnerability, active exploitation, or intelligence about imminent attack. The company reached customers by direct email, a channel that implies urgency beyond standard security advisory processes.

ShareFile is marketed as an enterprise-grade secure file-sharing and collaboration platform. Its Storage Zone Controller component allows organizations to store files on their own infrastructure while managing access through ShareFile's control plane. Healthcare entities that adopted ShareFile for handling clinical documents, referral attachments, or administrative file exchange between locations may have Storage Zone Controllers running in their environments.

The shutdown guidance is a containment-first response — consistent with how vendors handle threats where a patch is not yet available or where exploitation is believed to be active or imminent.

Why this matters for healthcare operators

File-sharing platforms occupy a sensitive position in healthcare workflows. They frequently carry documents that include protected health information: discharge summaries, imaging reports, insurance records, and signed consent forms. A compromise of on-premises file-hosting infrastructure can expose that content without triggering the access-log alerts that electronic health record systems typically generate, because the files sit outside the EHR's audit trail.

Progress Software has faced this type of situation before. Its MOVEit Transfer software was the target of a 2023 mass-exploitation campaign by the Cl0p ransomware group that affected hundreds of organizations, including numerous healthcare entities and their business associates. That incident demonstrated how a single vulnerability in a widely deployed managed-file-transfer product can cascade across an entire industry in days.

Organizations that use ShareFile under a business associate agreement should review that agreement now to confirm notification obligations if the threat materializes into a confirmed breach.

What administrators should do now

The immediate priority is determining whether any ShareFile Storage Zone Controllers are running in the environment. IT teams at practices and health systems that rely on managed services or assume ShareFile is entirely cloud-hosted should verify that assumption — Storage Zone Controllers are sometimes deployed by implementation partners without explicit documentation to clinical or compliance staff.

If controllers are confirmed to be running, Progress's guidance is to shut them down until further instruction. Administrators should:

What this signals about on-premises file-transfer risk

The ShareFile alert arrives as healthcare organizations continue to weigh the risk profile of on-premises managed-file-transfer infrastructure against cloud-hosted alternatives. The MOVEit episode shifted that calculus for many compliance teams, but on-premises deployments persist where regulatory, contractual, or connectivity constraints make cloud hosting difficult.

The pattern — a vendor issuing a preemptive shutdown advisory rather than a patch — suggests the threat is either not yet fully characterized or that no fix is ready for immediate deployment. For compliance officers, that ambiguity is itself a risk management signal: when a vendor cannot yet describe the threat precisely enough to offer a targeted mitigation, a broad defensive action like shutting down the affected component is the only available control. Practices that have documented their file-transfer architecture and maintain current vendor contact relationships will execute that response faster than those operating on institutional memory alone.