Progress SoftwareCVE-2026-65941
Progress Software WhatsUp Gold: remote code execution
High8.8CVE-2026-65941 · Published Aug 12, 2026 · updated Sep 2, 2026
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WhatsUp Gold Product | < 26.0.2 | 26.0.2 |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: insecure default permissions | Medium6.8 | 26.0.2 |