Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-66145PATCHED
sonicwall · gms

CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version

Description

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

Affected Products

VendorProductVersions
sonicwallgms9.5.1 and earlier versions

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallgmscert_advisory90%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories8h ago
[NEU] [hoch] SonicWall GMS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17h ago
Multiples vulnérabilités dans les produits SonicWall (12 août 2026)
→ No new info (linked only)
Tier C
VulDB21h ago
CVE-2026-66145 | SonicWall GMS up to 9.5.1/9510.1044 os command injection
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
CWECWE-94
PublishedAug 11, 2026
Trending Score58
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-15409EXP
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 88
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 78
CRITICALCVE-2026-66147
CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Trending: 58
HIGHCVE-2026-66149
CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 50
HIGHCVE-2026-66150
CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 12, 2026