SonicWallCVE-2026-66145
SonicWall GMS: remote code execution
Critical9.1CVE-2026-66145 · Published Aug 11, 2026 · updated Aug 28, 2026
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GMS Product | <= 9.5.1 and earlier versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-94
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: command injection | Critical9.4 | No fix yet |
| Aug 11 | SonicWall GMS: command injection | Medium6.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: improper certificate validation | High8.3 | No fix yet |
| Aug 11 | SonicWall GMS: unsafe deserialization | High8.4 | No fix yet |