MEDIUM 6.8 NVD
CVE-2026-65939
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
References
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2026
- https://docs.progress.com/bundle/whatsupgold-release-notes-26-0/page/WhatsUp-Gold-2026.0-R
- https://www.progress.com/network-monitoring
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10467 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.