<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Cleo Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Cleo.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 &amp; CVE-2026-2701)</title><link>https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701</link><guid isPermaLink="false">cst-561</guid><description>Researchers discovered and chained two vulnerabilities in Progress ShareFile's Storage Zone Controller (an on-premises gateway managing file transfers) to achieve unauthenticated remote code execution. The flaws, CVE-2026-2699 (authentication bypass) and CVE-2026-2701 (remote code execution), affected version 5.12.3 on the ASP.NET branch and were patched in version 5.12.4 released March 10, 2026. Approximately 30,000 Storage Zone Controller instances are exposed on the internet.</description><pubDate>Thu, 02 Apr 2026 10:00:42 GMT</pubDate></item><item><title>Cleo Software Actively Being Exploited in the Wild | Huntress</title><link>https://huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild</link><guid isPermaLink="false">cst-901</guid><description>Huntress has detected active exploitation of three Cleo file transfer management products (LexiCom, VLTransfer, and Harmony) in the wild, tracked as CVE-2024-55956. The vulnerability is being actively exploited against organizations using these widely deployed solutions.</description><pubDate>Mon, 06 Jan 2025 21:16:42 GMT</pubDate></item><item><title>Cleo Malichus Malware Analysis CVE-2024-55956| Huntress</title><link>https://huntress.com/blog/cleo-software-vulnerability-malware-analysis</link><guid isPermaLink="false">cst-908</guid><description>Huntress security researchers have analyzed CVE-2024-55956, a vulnerability in Cleo software, and documented a new malware family they named Malichus. The analysis provides technical details on how the vulnerability is being exploited in the wild.</description><pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate></item></channel></rss>