CVE-2026-66145Patch

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-13); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-12: 1Mentions · 2026-08-13: 2Mentions · 2026-08-31: 2PoC Mentioned / Linked · 2026-08-31: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-31: 2Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-31: 208-1208-1308-31
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
Exploit
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-121
Patch1
2026-08-132
Disclosure1Patch1
2026-08-312
Exploit1Patch1
Full discourse5 posts
  • T1erOne@tieroneforum
    Exploit

    Цепочка эксплуатации SonicWall GMS: обход патчей для pre-auth RCE as root (CVE-2026-66145) https://tier1.life/thread/556 https://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/556 #articles #SonicWall #RCE @buffaloverflow

    Post summary

    The shared thread presents a chain of exploitation for SonicWall GMS, detailing how patch bypass techniques enable a pre‑authentication remote code execution as root (CVE‑2026‑66145).

    00020358
    317 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『We recently revisited those patches and found that none of the underlying root causes were fixed - every original CVE remained exploitable,』😩 SonicWall GMS - Unauthenticated RCE and Encrypted Password Hash Extraction (CVE-2026-66145) https://blog.amberwolf.com/blog/2026/august/sonicwall-gms-unauthenticated-rce-and-encrypted-password-hash-extraction/

    Post summary

    The post notes that patches applied to CVE‑2026‑66145 failed to fix underlying root causes, leaving the vulnerability exploitable, highlighting the need for proper remediation.

    00020301
    7.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities in #SonicWall Global Management System (GMS), including critical flaws allowing unauthenticated remote code execution (CVE-2026-66145, CVE-2026-66147). Advisory at: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011 #Patch #Patch #Patch

    Post summary

    The advisory warns of critical unauthenticated RCE vulnerabilities in SonicWall Global Management System and directs readers to a patch via the provided URL.

    01000380
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 1) CVE-2026-66145 - An unauthenticated remote code execution vulnerability 3) CVE-2026-66147 - GMS Unauthenticated Command Injection in Dispatcher Service SonicWall GMS Security Affected By Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011

    Post summary

    The message announces two new SonicWall GMS vulnerabilities—CVE‑2026‑66145 (unauthenticated RCE) and CVE‑2026‑66147 (command injection)—without providing patches, PoC, or evidence of active exploitation.

    00000457
    7.0K followersView on X
  • TECHEPAGES@techepages
    Patch

    SonicWall has released patches for eight vulnerabilities, including two critical RCE flaws (CVE-2026-66147, CVE-2026-66145) in its discontinued Global Management System (GMS). The issues could allow unauthenticated remote code execution and data disclosure. Fixes are available in GMS v9.5.2 and Email Security v10.0.36.

    Post summary

    SonicWall disclosed that patches are available for eight vulnerabilities, including two critical RCE flaws CVE-2026-66147 and CVE-2026-66145 in a discontinued GMS, with fixes in GMS v9.5.2 and Email Security v10.0.36.

    0000038
    38 followersView on X

Explore more