In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
https://www.securityweek.com/exploitation-long-known-for-most-of-cisas-latest-kev-additions/
https://www.infosecurity-magazine.com/news/cisa-govt-patch-exploited-cisco/
https://thehackernews.com/2025/03/cisco-hitachi-microsoft-and-progress.html
https://thehackernews.com/2024/09/progress-whatsup-gold-exploited-just.html
https://www.trendmicro.com/en_us/research/24/i/whatsup-gold-rce.html
https://www.progress.com/network-monitoring
https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024