All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-65939
MEDIUMpublished 2026-08-12 16:17 UTC · 11 hours ago · modified 2026-08-12 18:18 UTC
6.8
CVSS / 10
// description
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
// weaknesses (CWE)
- CWE-22
- CWE-73
- CWE-434