---
id: CVE-2026-65941
title: "In WhatsUp Gold versions released before 2026.0.2,\_an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account."
summary: "In WhatsUp Gold versions released before 2026.0.2,\_an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account."
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
  - CWE-94
  - CWE-306
  - CWE-918
published: '2026-08-12'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65941'
references:
  - url: >-
      https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2026
    label: security@progress.com
  - url: >-
      https://docs.progress.com/bundle/whatsupgold-release-notes-26-0/page/WhatsUp-Gold-2026.0-Release-Notes.html
    label: security@progress.com
  - url: 'https://www.progress.com/network-monitoring'
    label: security@progress.com
tags:
  - nvd
epss: 0.00678
epssPercentile: 0.50197
ingestedAt: '2026-08-29T20:41:56.306Z'
---

## Overview

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
