Junglewise Threat Intelligence

CVE-2026-65937: Progress WhatsUp Gold persistent XSS via frontend bypass

CVE-2026-65937 · Severity: high · CVSS 8 · Published 2026-08-12

Technologies: Progress WhatsUp Gold. Vendors: Progress.

Executive brief

WhatsUp Gold is a network monitoring and management platform used by enterprises to monitor infrastructure and application health. An authenticated attacker can bypass frontend security controls and inject malicious scripts that persist in the application, potentially allowing them to steal sensitive data, compromise monitoring integrity, or perform actions on behalf of legitimate users.

Technical details

This vulnerability is a persistent cross-site scripting (XSS) flaw in WhatsUp Gold versions before 2026.0.2. An authenticated attacker can bypass frontend validation controls to inject script content that is stored and executed when other users access the affected application. The vulnerability requires valid authentication credentials to exploit. A successful attack allows the attacker to execute arbitrary JavaScript in the context of other users' browsers, enabling session hijacking, credential theft, or lateral movement within the monitoring environment. Progress has patched this issue in WhatsUp Gold 2026.0.2 released on August 12, 2026.

Affected products

  • Progress WhatsUp Gold before 2026.0.2

Timeline

  • 2026-08-12: disclosed: CVE-2026-65937 published
  • 2026-08-12: patched: Fixed in WhatsUp Gold 2026.0.2

References

Related threats