Progress SoftwareCVE-2026-65940
Progress Software WhatsUp Gold: insecure default permissions
Medium6.8CVE-2026-65940 · Published Aug 12, 2026 · updated Sep 2, 2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WhatsUp Gold Product | < 26.0.2 | 26.0.2 |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |