In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress Software
Progress Software whatsup Gold |
|
| Vendors & Products |
Progress Software
Progress Software whatsup Gold |
Wed, 12 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |
| Title | WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service. | |
| Weaknesses | CWE-306 CWE-73 CWE-918 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-12T16:10:40.937Z
Reserved: 2026-07-23T16:08:34.531Z
Link: CVE-2026-65941
Updated: 2026-08-12T16:10:33.439Z
Status : Received
Published: 2026-08-12T16:17:14.050
Modified: 2026-08-12T17:17:29.610
Link: CVE-2026-65941
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:15:07Z