Sceawere
Vulnerability Detail
CVE-2026-65941UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WhatsUp Gold Unauthenticated Remote Code Execution
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Progress Software Corporation
- Product
- WhatsUp Gold
- Attack Type
- CWE-306 Missing authentication for critical function
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-12T16:17:14.050Z",
"pubdate": "2026-08-12T16:17:14.050Z",
"executiveSummary": "An unauthenticated remote code execution vulnerability exists in WhatsUp Gold versions released before 2026.0.2. This security flaw enables remote attackers possessing network access to the affected service to execute arbitrary code within the execution context of the Internet Information Services (IIS) application service account. The presence of this vulnerability introduces severe operational and security risks, potentially leading to complete system compromise, unauthorized data exfiltration, lateral movement within the internal network, and persistent unauthorized access to the underlying infrastructure hosting the application. The exploitation requirements are minimal, necessitating only network reachability to the vulnerable service without requiring prior authentication or valid user credentials. This represents a critical severity threat vector that requires immediate remediation to safeguard enterprise environments against potential exploitation attempts.",
"technicalDetails": "The vulnerability resides within the WhatsUp Gold application architecture running on Internet Information Services (IIS). The root cause stems from improper input validation or insecure handling of incoming requests processed by the vulnerable component of the service. Because the application exposes network-accessible endpoints that process external data streams without requiring authentication, an unauthenticated remote attacker can interact directly with the vulnerable service.\nThe attack flow begins when an attacker with network access crafts a malicious payload designed to exploit the logic flaw within the application. The attacker transmits this crafted request across the network to the exposed service endpoint. Upon receipt, the vulnerable component processes the malicious input unsafely, triggering the execution flow anomaly. This allows the injected instructions or commands to be processed and executed by the underlying runtime environment.\nBecause the application executes within the context of the IIS application service account, successful execution of the payload grants the attacker the privileges associated with that service account. Depending on the configuration of the IIS environment, this access level may permit the execution of arbitrary operating system commands, manipulation of local files, interaction with connected databases, and further post-exploitation activities.\nThe affected product is WhatsUp Gold, specifically targeting all versions released prior to 2026.0.2. Exploitation prerequisites are strictly limited to network accessibility to the service and the absence of authentication barriers, meaning any network-adjacent or externally exposed instance lacking adequate perimeter defenses is susceptible to remote compromise without prior privilege escalation."
}