CVE-2026-65941

8.8

Progress Software Corporation · WhatsUp Gold

Progress WhatsUp Gold contains multiple critical vulnerabilities, including missing authentication and server-side request forgery, allowing potential system compromise.

Executive summary

Critical vulnerabilities in Progress WhatsUp Gold allow unauthenticated attackers to perform unauthorized actions and exploit server-side request forgery to compromise the network management system.

Vulnerability

This issue involves missing authentication for critical functions (CWE-306), server-side request forgery (CWE-918), and path manipulation (CWE-73). The vulnerability is accessible via the adjacent network and does not require user interaction.

Business impact

The CVSS score of 8.8 reflects the high impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to bypass security mechanisms to gain full access to the network management platform, potentially leading to widespread network disruption and data exfiltration.

Remediation

Immediate Action: Upgrade to WhatsUp Gold version 26.0.2 or later as specified in the Progress Software security bulletin.

Proactive Monitoring: Inspect network traffic for suspicious requests directed toward the WhatsUp Gold server, particularly those attempting to trigger internal requests or unauthorized file access.

Compensating Controls: Restrict access to the WhatsUp Gold management interface to a dedicated, isolated management network and utilize a WAF to filter malicious traffic.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The combination of SSRF and missing authentication makes this a high-priority vulnerability. System administrators should apply the vendor-provided update immediately to secure their network monitoring infrastructure.

More Progress Software Corporation CVEs