logo

Critical Progress WhatsUp RCE flaw now under active exploitation

ID: c1e61eaa-8448-5105-906b-2d19f7d81a33

STIX ID: report--c1e61eaa-8448-5105-906b-2d19f7d81a33

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-08-07

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

Progress WhatsUp Gold versions 23.1.2 and older are vulnerable to CVE-2024-4885, a critical unauthenticated remote code execution flaw (CVSS 9.8). Public proof-of-concept exploits target the /NmAPI/RecurringReport endpoint and Shadowserver reported exploitation attempts from six IPs beginning August 1, 2024; administrators are advised to upgrade to 23.1.3, restrict endpoint access to trusted IPs/behind VPNs or firewalls, and monitor for suspicious activity and potential webshells.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.