Progress WhatsUp Gold: Five Vulnerabilities Including RCE and XSS Disclosed Together
Key findings • Five vulnerabilities in Progress WhatsUp Gold disclosed on August 12, 2026. • Includes a critical RCE flaw (CVE-2026-65941) and an XSS vulnerability (CVE-2026-65937). • Pat…

Key findings
- Five vulnerabilities in Progress WhatsUp Gold disclosed on August 12, 2026.
- Includes a critical RCE flaw (CVE-2026-65941) and an XSS vulnerability (CVE-2026-65937).
- Patch available in WhatsUp Gold version 2026.0.2.
- Vulnerabilities affect unauthenticated and authenticated users.
- Flaws include arbitrary code execution, arbitrary file writes, and persistent script injection.
On August 12, 2026, Progress disclosed five vulnerabilities affecting its WhatsUp Gold network monitoring software. The batch of vulnerabilities, all patched in version 2026.0.2, includes a critical remote code execution flaw and several other medium-severity issues. These disclosures highlight potential risks for organizations relying on WhatsUp Gold for network oversight.
The most severe vulnerability, CVE-2026-65941, is an unauthenticated remote code execution flaw. This high-severity bug (CVSSv3 8.8) allows an attacker with network access to execute arbitrary code on the server in the context of the IIS application service account. This could lead to a complete system compromise.
Several other vulnerabilities impact authenticated users. CVE-2026-65940, a medium-severity flaw (CVSSv3 6.8), permits a privileged attacker to write arbitrary files to a web-accessible location. Similarly, CVE-2026-65939, also rated medium (CVSSv3 6.8), allows a privileged attacker to create a LogToFile action that specifies an arbitrary file extension within the IIS web root, potentially enabling further manipulation of server files.
Further complicating the security landscape, CVE-2026-65937, a high-severity (CVSSv3 8.0) vulnerability, allows an authenticated attacker to bypass frontend controls and inject persistent script content, leading to cross-site scripting (XSS) attacks. Another medium-severity issue, CVE-2026-65938 (CVSSv3 4.3), involves an improper authorization vulnerability in the Scheduled Reports API, enabling any authenticated user to trigger restricted actions.
All five vulnerabilities were addressed in WhatsUp Gold version 2026.0.2. Organizations using WhatsUp Gold should prioritize updating to this patched version to mitigate the risks associated with these newly disclosed security weaknesses. The coordinated disclosure of these flaws underscores the importance of timely patching for network monitoring solutions, which often have privileged access to critical infrastructure.