Unauthenticated Remote Code Execution Vulnerability in GMS by SonicWall
CVE-2026-66145
9.1CRITICAL
What is CVE-2026-66145?
An unauthenticated remote code execution vulnerability exists in versions of GMS 9.5.1 and earlier, allowing a remote attacker to exploit the zipslip vulnerability. This can lead to unauthorized access, enabling the attacker to read sensitive data and write arbitrary files to the server, posing a significant risk to system integrity and confidentiality.
Affected Version(s)
GMS Windows 9.5.1 and earlier versions