Skip to content
SonicWallCVE-2026-66145

SonicWall GMS: remote code execution

Critical9.1CVE-2026-66145 · Published Aug 11, 2026 · updated Aug 28, 2026

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

SonicWall advisory

Affected versions

PackageAffectedFixed in
GMS
Product
<= 9.5.1 and earlier versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-94

More SonicWall advisories

All SonicWall
Advisory
SonicWall GMS: command injection
Critical9.4Aug 11
SonicWall GMS: command injection
Medium6.3Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall GMS: improper certificate validation
High8.3Aug 11
SonicWall GMS: unsafe deserialization
High8.4Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.