Progress SoftwareCVE-2026-65939
Progress Software WhatsUp Gold: path traversal
Medium6.8CVE-2026-65939 · Published Aug 12, 2026 · updated Sep 2, 2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WhatsUp Gold Product | < 26.0.2 | 26.0.2 |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: insecure default permissions | Medium6.8 | 26.0.2 |