CVE-2026-65939
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2026-65939 is an arbitrary file write vulnerability in Progress Software's WhatsUp Gold network monitoring platform that allows a privileged attacker to create a LogToFile action specifying an arbitrary file extension within the IIS web root. It affects all WhatsUp Gold versions released before 2026.0.2, which was released on August 12, 2026. The vulnerability was disclosed on August 12, 2026, alongside several other CVEs addressed in the same security bulletin. It carries a CVSS v3.1 base score of 6.8 (Medium), reflecting the requirement for high privileges and adjacent network access (Github Advisory, Progress Release Notes).

Technical details

The vulnerability is rooted in insufficient validation of file extension input when configuring LogToFile actions in WhatsUp Gold, classified under CWE-22 (Path Traversal), CWE-73 (External Control of File Name or Path), and CWE-434 (Unrestricted Upload of File with Dangerous Type). A privileged attacker on an adjacent network can abuse the LogToFile action configuration to write files with arbitrary extensions — including executable types such as .aspx — directly into the IIS web root directory. This effectively enables the attacker to plant a web shell or other malicious file in a web-accessible location, which can then be triggered via an HTTP request to achieve code execution. No public proof-of-concept code has been identified at this time (Github Advisory, Progress Release Notes).

Impact

Successful exploitation can lead to arbitrary code execution on the WhatsUp Gold server, with full confidentiality, integrity, and availability impact on the affected system. An attacker who plants a web shell in the IIS web root can execute commands in the context of the IIS application pool, potentially enabling lateral movement within the network, credential harvesting, and exfiltration of sensitive monitoring data including network topology, credentials, and device configurations stored by WhatsUp Gold (Github Advisory).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of disclosure. The attack vector is adjacent network (AV:A), requiring the attacker to already possess high privileges within the WhatsUp Gold application, which significantly limits the exploitability surface. The EPSS score is approximately 0.238%, placing it in the 15th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a WhatsUp Gold instance running a version prior to 2026.0.2 accessible from an adjacent network segment, and obtain or compromise a privileged (administrative) account on the platform.
  2. Access LogToFile Action Configuration: Log in to the WhatsUp Gold web interface with the privileged account and navigate to the Actions configuration section where LogToFile actions can be created or modified.
  3. Specify Arbitrary File Extension: When creating a new LogToFile action, supply a file path targeting the IIS web root directory with a dangerous file extension (e.g., .aspx, .asp) instead of a benign log extension.
  4. Inject Malicious Content: Configure the log action to write attacker-controlled content (e.g., an ASP.NET web shell payload) as the log output, so that when the action is triggered, the malicious file is written to the web root.
  5. Trigger the Action: Cause the LogToFile action to execute (e.g., by triggering an alert or event that invokes the action), resulting in the web shell being written to the IIS web root.
  6. Execute Commands: Access the written file via an HTTP request to the WhatsUp Gold web server (e.g., https://<target>/shell.aspx) to achieve remote code execution on the server (Github Advisory).

Indicators of compromise

  • File System: Unexpected files with executable extensions (.aspx, .asp, .php) appearing in the IIS web root directory of the WhatsUp Gold installation; new or modified files in web-accessible directories not associated with normal application updates.
  • Logs: IIS access logs showing HTTP requests to unexpected or newly created files in the web root (e.g., GET /shell.aspx); WhatsUp Gold application logs recording creation of LogToFile actions with unusual file paths or extensions.
  • Process: Unusual child processes spawned by the IIS worker process (w3wp.exe), such as cmd.exe, powershell.exe, or network utilities like curl or certutil.
  • Network: Outbound connections from the WhatsUp Gold server to unknown external IP addresses, particularly on non-standard ports, originating from the IIS worker process.

Mitigation and workarounds

Progress Software has released WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65939 along with several other security issues. Organizations should upgrade to version 2026.0.2 or later as the primary remediation. As interim mitigations, administrators should restrict network access to the WhatsUp Gold administration interface to trusted network segments only, limit administrative account privileges to trusted personnel, and implement file system ACLs to restrict write access to the IIS web root directory (Progress Release Notes, Github Advisory).

Community reactions

Progress Software addressed CVE-2026-65939 as part of a broader August 2026 security bulletin that patched multiple CVEs (CVE-2026-65937 through CVE-2026-65941) in WhatsUp Gold 2026.0.2. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Progress Release Notes).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65941HIGH8.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65937HIGH8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65940MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65939MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65938MEDIUM4.3
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management