CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and ea...
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Security readout for executives and security teams
Plain-English summary
SonicWall GMS 9.5.1 Build 9510.1044 and earlier reportedly allow an unauthenticated remote attacker to access sensitive data and write arbitrary files. Because no credentials or user interaction are required, exposed systems could face serious compromise. The supplied sources do not establish availability impact or confirmed exploitation.
Executive priority
Treat reachable affected GMS systems as an immediate remediation priority because compromise requires neither authentication nor user interaction and may expose data or alter files. First establish inventory and external reachability, then follow SonicWall guidance. Escalate any unexplained file modifications or sensitive-data access for incident investigation.
Technical view
The vulnerability is described as unauthenticated remote code execution involving Zip Slip, enabling sensitive-data reads and arbitrary file writes. CVSS 3.1 is 9.1: network-accessible, low complexity, no privileges, no interaction, with high confidentiality and integrity impact but no scored availability impact. The supplied record assigns CWE-94, although detailed attack-path evidence is limited.
Likely exposure
Exposure applies to SonicWall GMS 9.5.1 Build 9510.1044 and earlier versions. Risk is greatest where a vulnerable GMS interface is reachable from untrusted networks. The bundle provides no CPEs, deployment prerequisites, affected component details, or confirmed default exposure, so organizations must verify their installed build and network accessibility.
Exploitation context
The supplied bundle marks this CVE as absent from KEV and provides no evidence of active exploitation, public proof-of-concept code, or observed attacks. Its unauthenticated network attack vector and low complexity nevertheless make reachable vulnerable systems attractive targets. Do not interpret critical severity alone as proof of exploitation.
Researcher notes
The public bundle is sparse. It links Zip Slip to arbitrary file write and labels the issue remote code execution, but supplies no vulnerable endpoint, archive-processing flow, prerequisites, patch version, or exploitation evidence. CVSS explicitly scores availability impact as none. Validate product build and advisory updates without assuming every file write automatically yields code execution.
Mitigation direction
Inventory SonicWall GMS deployments and identify versions and exact build numbers.
Consult the SonicWall advisory for current remediation or upgrade guidance.
Restrict GMS access to trusted administrative networks while remediation is assessed.
Monitor vendor guidance for clarification of affected versions and available fixes.
Validation and detection
Confirm whether each deployment runs GMS 9.5.1 Build 9510.1044 or earlier.
Determine whether vulnerable GMS services are reachable from untrusted networks.
Review logs and file changes for unexplained access or writes.
Recheck the SonicWall advisory after remediation and confirm the installed build.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-94: Code execution behavior lookup
Code execution and unsafe deserialization weaknesses often justify reviewing execution behavior and process telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-94 · source CWE mapping
Improper Control of Generation of Code ('Code Injection')
Improper Control of Generation of Code ('Code Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.