CVE-2026-66147 – SonicWall GMS
CVSS 9.4
CRITICAL
Critical - Same Day Deployment
“Critical flaws expose vulnerable GMS systems to remote compromise without authentication.”
SonicWall GMS is affected by two critical remote code execution vulnerabilities in GMS 9.5.1 and earlier versions. CVE-2026-66147 is a command injection vulnerability in the GMS Dispatcher Service that allows an unauthenticated remote attacker to execute code through specially crafted requests. CVE-2026-66147 has a CVSS score of 9.4, Critical severity.
CVE-2026-66145 allows an unauthenticated remote attacker to read sensitive data and perform arbitrary file writes through a Zip Slip condition, creating a path to remote code execution. CVE-2026-66145 has a CVSS score of 9.1, Critical severity.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-94
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.