
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65941 is a remote code execution vulnerability in Progress Software's WhatsUp Gold network monitoring software affecting all versions released before 2026.0.2. An unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. The vulnerability was published on August 12, 2026, and patched in version 2026.0.2 released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, Progress Release Notes).
The vulnerability is classified under multiple CWEs: CWE-73 (External Control of File Name or Path), CWE-94 (Improper Control of Generation of Code / Code Injection), CWE-306 (Missing Authentication for Critical Function), and CWE-918 (Server-Side Request Forgery). The attack vector is Adjacent Network (AV:A), meaning the attacker must have network-level access to the WhatsUp Gold service but does not require authentication or user interaction. The root cause involves missing authentication controls on a critical function combined with improper handling of user-controlled file paths or code generation, enabling an attacker to inject and execute arbitrary code through the IIS-hosted application (Github Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the IIS application service account, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could access sensitive network monitoring data, modify configurations, disrupt monitoring operations, or use the compromised server as a pivot point for lateral movement within the network. Given that WhatsUp Gold is a network management platform with visibility into the broader infrastructure, compromise of this system could expose credentials, device configurations, and network topology data (Github Advisory, Progress Release Notes).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.437% (37th percentile), indicating a relatively low near-term exploitation probability. The attack complexity is Low and no privileges or user interaction are required, though the Adjacent Network attack vector limits the exposure compared to fully internet-facing vulnerabilities.
Progress Software released a patch in WhatsUp Gold version 2026.0.2 on August 12, 2026, which addresses CVE-2026-65941 along with several other security issues (CVE-2026-65937 through CVE-2026-65940). Organizations should upgrade to version 2026.0.2 or later immediately. As interim mitigations, restrict network access to the WhatsUp Gold service to trusted systems only and implement network segmentation to limit exposure of the affected IIS-hosted service (Progress Release Notes, Github Advisory).
The vulnerability was assigned by Progress Software Corporation and disclosed alongside a security bulletin published to the Progress community portal in August 2026. Automated vulnerability tracking services including CVEFeed, VulDB, and Radar/Offseq indexed the CVE shortly after publication, indicating routine community monitoring of WhatsUp Gold security issues given the product's history of high-severity vulnerabilities (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."