Skip to content
Progress SoftwareCVE-2026-65939

Progress Software WhatsUp Gold: path traversal

Medium6.8CVE-2026-65939 · Published Aug 12, 2026 · updated Sep 2, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

Progress Software advisory

Affected versions

PackageAffectedFixed in
WhatsUp Gold
Product
< 26.0.226.0.2
Details and references

More Progress Software advisories

All Progress Software

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.