nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66145 CVE-2026-66145
CRITICAL
SonicWall GMS Unauthenticated Remote Code Execution via ZipSlip
Record summary
CVE-2026-66145 has a selected CVSS score of 9.1 (critical).
Description
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 9.5.1 and earlier versions | affected |
References
2psirt.global.sonicwall.comVendor advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011