Skip to content
Progress SoftwareCVE-2026-65937

Progress Software WhatsUp Gold: cross-site scripting

High8.0CVE-2026-65937 · Published Aug 12, 2026 · updated Sep 2, 2026

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

Progress Software advisory

Affected versions

PackageAffectedFixed in
WhatsUp Gold
Product
< 26.0.226.0.2
Details and references

More Progress Software advisories

All Progress Software

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.