SonicWallCVE-2026-66146
SonicWall GMS: cross-site scripting
Medium6.1CVE-2026-66146 · Published Aug 11, 2026 · updated Aug 28, 2026
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GMS Product | <= 9.5.1 and earlier versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-79
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: command injection | Critical9.4 | No fix yet |
| Aug 11 | SonicWall GMS: command injection | Medium6.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: improper certificate validation | High8.3 | No fix yet |
| Aug 11 | SonicWall GMS: unsafe deserialization | High8.4 | No fix yet |