CVE-2018-8939: Progress WhatsUp Gold

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information about the WhatsUp Gold system, or (3) execute remote commands.

Affected products

  • Progress WhatsUp Gold: before 18.0 (fixed in 18.0)

Published 2018-05-01. Last modified 2026-06-17.