Critical severity9.1NVD Advisory· Published Aug 11, 2026· Updated Aug 28, 2026
CVE-2026-66145
CVE-2026-66145
Description
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
2- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- SonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformSecurityWeek · Aug 12, 2026