Executive brief
WhatsUp Gold is a network monitoring and management platform used by organizations to track infrastructure health and performance. An unauthenticated remote attacker with network access to the service can execute arbitrary code with the privileges of the IIS application service account, potentially leading to complete compromise of the monitoring infrastructure and unauthorized access to monitored systems.
Technical details
This vulnerability allows unauthenticated remote code execution on WhatsUp Gold deployments. The vulnerability exists in versions released before 2026.0.2 and is reachable over the network without requiring prior authentication. An attacker can exploit this flaw to execute arbitrary code in the context of the IIS application service account, gaining the ability to compromise the monitoring platform and potentially pivot to monitored infrastructure. The vulnerability was patched in version 2026.0.2 released on August 12, 2026.
Affected products
- Progress WhatsUp Gold before 2026.0.2
Timeline
- 2026-08-12: disclosed
- 2026-08-12: patched: Fixed in version 2026.0.2