【Vulnerability Alert】SonicWall GMS Contains Two Critical Cybersecurity Vulnerabilities

publish date : 2026-08-21 update date : 2026-08-21

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026081404083737 Publication Time 2026-08-14 16:15:38
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-14 16:15:38
Impact Level Low  
[Subject]
【Vulnerability Alert】SonicWall GMS Contains Two Critical Cybersecurity Vulnerabilities
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000011

SonicWall issued an advisory regarding two critical cybersecurity vulnerabilities affecting its GMS product (CVE-2026-66145, CVSS: 9.1, and CVE-2026-66147, CVSS: 9.4). CVE-2026-66145 is an unauthenticated remote code execution vulnerability that allows a remote attacker to read sensitive data and perform arbitrary file writes through Zip Slip; CVE-2026-66147 is an unauthenticated command injection vulnerability that allows a remote attacker to execute remote code through specially crafted requests.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

SonicWall GMS version 9.5.1 and earlier

[Recommended Actions]

Please update SonicWall GMS to version 9.5.2 or later

[Reference]

https://www.twcert.org.tw/tw/cp-169-11103-13b85-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center