[Security Vulnerability Alert] SonicWall GMS has two major security vulnerabilities.

 
2026/8/18 ~ 2027/2/18
View Count:38

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202608-00000011

[Content Description]
SonicWall has released a critical cybersecurity vulnerability bulletin for its product GMS (CVE-2026-66145, CVSS: 9.1 and CVE-2026-66147, CVSS: 9.4). CVE-2026-66145 is an unauthenticated remote code execution vulnerability, allowing a remote attacker to read sensitive data and perform arbitrary file writes via zipslip; CVE-2026-66147 is an unauthenticated command injection vulnerability, allowing a remote attacker to execute remote code through a carefully crafted request.

[Affected Platforms]
SonicWall GMS versions 9.5.1 and earlier

[Recommended Action]
Please update SonicWall GMS to version 9.5.2 or later.

[References]
1. https://www.twcert.org.tw/tw/cp-169-11103-13b85-1.html

Files
system_update_alt參考資料
Top↑