Critical severity9.4NVD Advisory· Published Aug 11, 2026· Updated Aug 28, 2026
CVE-2026-66147
CVE-2026-66147
Description
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Affected products
1- Range: <=9.5.1
Patches
Vulnerability mechanics
References
1News mentions
2- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- SonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformSecurityWeek · Aug 12, 2026