PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65941 Progress Software Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T16:17:14.050Z and has not been modified since then. CVE-2026-65941 is a high-severity vulnerability affecting WhatsUp Gold versions before 2026.0.2, allowing unauthenticated remote attackers to execute arbitrary code in the context of the IIS application service account. This vulnerability has a CVSS score of 8.8 and a severity rating of HIGH. The vulnerability affects WhatsUp Gold installations, particularly those with network-exposed instances. IT administrators and security teams responsible for WhatsUp Gold installations should prioritize patching to prevent potential code execution. Evidence is limited to the official CVE Program record and NIST NVD detail page. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Vendor
Progress Software Corporation
Product
WhatsUp Gold
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

IT administrators and security teams responsible for WhatsUp Gold installations, particularly those with network-exposed instances, should prioritize patching to prevent potential code execution. This includes reviewing affected product deployments, assessing operational impact, and verifying affected scope and severity.

Technical summary

CVE-2026-65941 is a high-severity vulnerability in WhatsUp Gold versions before 2026.0.2, allowing unauthenticated remote attackers to execute arbitrary code in the context of the IIS application service account. This vulnerability affects WhatsUp Gold installations, particularly those with network-exposed instances. The vulnerability has a CVSS score of 8.8 and a severity rating of HIGH. Organizations using WhatsUp Gold versions before 2026.0.2 should prioritize patching to prevent potential code execution. The CVE record indicates that WhatsUp Gold versions before 2026.0.2 are vulnerable to unauthenticated remote code execution. The NVD entry is currently Awaiting Analysis. Evidence is limited to the official CVE Program record and NIST NVD detail page. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. WhatsUp Gold 2026.0 release notes and Progress security bulletin for WhatsUp Gold provide additional context.

Defensive priority

Organizations using WhatsUp Gold versions before 2026.0.2 should prioritize patching to prevent potential code execution.

Recommended defensive actions

  • Apply patches for WhatsUp Gold 2026.0.2 or later
  • Restrict network access to the affected service
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record indicates that WhatsUp Gold versions before 2026.0.2 are vulnerable to unauthenticated remote code execution. The NVD entry is currently Awaiting Analysis. Evidence is limited to the official CVE Program record and NIST NVD detail page. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-65941 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-65941

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-65941 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65941

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.