Junglewise Threat Intelligence

CVE-2026-65940: Progress WhatsUp Gold arbitrary file write to web-accessible location

CVE-2026-65940 · Severity: medium · CVSS 6.8 · Published 2026-08-12

Technologies: Progress WhatsUp Gold. Vendors: Progress.

Executive brief

WhatsUp Gold is a network monitoring and management platform used by organizations to track infrastructure health and availability. A privileged attacker with administrative access can exploit a flaw to write arbitrary files to directories accessible via the web server, potentially enabling remote code execution, configuration tampering, or exposure of sensitive data to unauthorized users.

Technical details

This vulnerability allows a privileged attacker to write arbitrary files to a web-accessible location on the WhatsUp Gold server. The attack requires existing administrative or elevated privileges on the system. By writing malicious files to web-accessible directories, an attacker can achieve code execution via HTTP requests, modify application behavior, or exfiltrate sensitive information. The vulnerability is present in versions prior to 2026.0.2, which was released on August 12, 2026. A patch is available in version 2026.0.2 and later.

Affected products

  • Progress WhatsUp Gold before 2026.0.2

Timeline

  • 2026-08-12: disclosed: CVE-2026-65940 published
  • 2026-08-12: patched: Fix released in WhatsUp Gold 2026.0.2

References

Related threats