CVE-2026-65941
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2026-65941 is a remote code execution vulnerability in Progress Software's WhatsUp Gold network monitoring software affecting all versions released before 2026.0.2. An unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. The vulnerability was published on August 12, 2026, and patched in version 2026.0.2 released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, Progress Release Notes).

Technical details

The vulnerability is classified under multiple CWEs: CWE-73 (External Control of File Name or Path), CWE-94 (Improper Control of Generation of Code / Code Injection), CWE-306 (Missing Authentication for Critical Function), and CWE-918 (Server-Side Request Forgery). The attack vector is Adjacent Network (AV:A), meaning the attacker must have network-level access to the WhatsUp Gold service but does not require authentication or user interaction. The root cause involves missing authentication controls on a critical function combined with improper handling of user-controlled file paths or code generation, enabling an attacker to inject and execute arbitrary code through the IIS-hosted application (Github Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the IIS application service account, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could access sensitive network monitoring data, modify configurations, disrupt monitoring operations, or use the compromised server as a pivot point for lateral movement within the network. Given that WhatsUp Gold is a network management platform with visibility into the broader infrastructure, compromise of this system could expose credentials, device configurations, and network topology data (Github Advisory, Progress Release Notes).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.437% (37th percentile), indicating a relatively low near-term exploitation probability. The attack complexity is Low and no privileges or user interaction are required, though the Adjacent Network attack vector limits the exposure compared to fully internet-facing vulnerabilities.

Mitigation and workarounds

Progress Software released a patch in WhatsUp Gold version 2026.0.2 on August 12, 2026, which addresses CVE-2026-65941 along with several other security issues (CVE-2026-65937 through CVE-2026-65940). Organizations should upgrade to version 2026.0.2 or later immediately. As interim mitigations, restrict network access to the WhatsUp Gold service to trusted systems only and implement network segmentation to limit exposure of the affected IIS-hosted service (Progress Release Notes, Github Advisory).

Community reactions

The vulnerability was assigned by Progress Software Corporation and disclosed alongside a security bulletin published to the Progress community portal in August 2026. Automated vulnerability tracking services including CVEFeed, VulDB, and Radar/Offseq indexed the CVE shortly after publication, indicating routine community monitoring of WhatsUp Gold security issues given the product's history of high-severity vulnerabilities (Github Advisory).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65941HIGH8.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65937HIGH8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65940MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65939MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65938MEDIUM4.3
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management