ZeroHour

CVE-2026-65941

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
Description

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

Vendors
progress
Products
whatsup gold
Weakness
CWE-73, CWE-94, CWE-306, CWE-918
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.