
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65939 is an arbitrary file write vulnerability in Progress Software's WhatsUp Gold network monitoring platform that allows a privileged attacker to create a LogToFile action specifying an arbitrary file extension within the IIS web root. It affects all WhatsUp Gold versions released before 2026.0.2, which was released on August 12, 2026. The vulnerability was disclosed on August 12, 2026, alongside several other CVEs addressed in the same security bulletin. It carries a CVSS v3.1 base score of 6.8 (Medium), reflecting the requirement for high privileges and adjacent network access (Github Advisory, Progress Release Notes).
The vulnerability is rooted in insufficient validation of file extension input when configuring LogToFile actions in WhatsUp Gold, classified under CWE-22 (Path Traversal), CWE-73 (External Control of File Name or Path), and CWE-434 (Unrestricted Upload of File with Dangerous Type). A privileged attacker on an adjacent network can abuse the LogToFile action configuration to write files with arbitrary extensions — including executable types such as .aspx — directly into the IIS web root directory. This effectively enables the attacker to plant a web shell or other malicious file in a web-accessible location, which can then be triggered via an HTTP request to achieve code execution. No public proof-of-concept code has been identified at this time (Github Advisory, Progress Release Notes).
Successful exploitation can lead to arbitrary code execution on the WhatsUp Gold server, with full confidentiality, integrity, and availability impact on the affected system. An attacker who plants a web shell in the IIS web root can execute commands in the context of the IIS application pool, potentially enabling lateral movement within the network, credential harvesting, and exfiltration of sensitive monitoring data including network topology, credentials, and device configurations stored by WhatsUp Gold (Github Advisory).
No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of disclosure. The attack vector is adjacent network (AV:A), requiring the attacker to already possess high privileges within the WhatsUp Gold application, which significantly limits the exploitability surface. The EPSS score is approximately 0.238%, placing it in the 15th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
.aspx, .asp) instead of a benign log extension.https://<target>/shell.aspx) to achieve remote code execution on the server (Github Advisory)..aspx, .asp, .php) appearing in the IIS web root directory of the WhatsUp Gold installation; new or modified files in web-accessible directories not associated with normal application updates.GET /shell.aspx); WhatsUp Gold application logs recording creation of LogToFile actions with unusual file paths or extensions.w3wp.exe), such as cmd.exe, powershell.exe, or network utilities like curl or certutil.Progress Software has released WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65939 along with several other security issues. Organizations should upgrade to version 2026.0.2 or later as the primary remediation. As interim mitigations, administrators should restrict network access to the WhatsUp Gold administration interface to trusted network segments only, limit administrative account privileges to trusted personnel, and implement file system ACLs to restrict write access to the IIS web root directory (Progress Release Notes, Github Advisory).
Progress Software addressed CVE-2026-65939 as part of a broader August 2026 security bulletin that patched multiple CVEs (CVE-2026-65937 through CVE-2026-65941) in WhatsUp Gold 2026.0.2. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Progress Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."