CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

  • Published Aug 11, 2026
  • CVSS 9.1 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-66145 at the National Vulnerability Database