← Browse

CVE-2026-66145

Medium

Elevated severity or exploit probability.

CVSS base
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS — probability of exploitation (30 days)
0.7%
49.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-94
Published 2026-08-11 · modified 2026-08-28

Description

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

References

Official: NVD · CVE.org