Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026081404083737 | Publication Time | 2026-08-14 16:15:38 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-14 16:15:38 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】SonicWall GMS Contains Two Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000011 SonicWall issued an advisory regarding two critical cybersecurity vulnerabilities affecting its GMS product (CVE-2026-66145, CVSS: 9.1, and CVE-2026-66147, CVSS: 9.4). CVE-2026-66145 is an unauthenticated remote code execution vulnerability that allows a remote attacker to read sensitive data and perform arbitrary file writes through Zip Slip; CVE-2026-66147 is an unauthenticated command injection vulnerability that allows a remote attacker to execute remote code through specially crafted requests. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
SonicWall GMS version 9.5.1 and earlier |
|||
|
[Recommended Actions] Please update SonicWall GMS to version 9.5.2 or later |
|||
|
[Reference] |
|||