CVE-2026-66145: exploitation status and patch state
CVE-2026-66145 · CVSS 9.1 CRITICAL
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Is CVE-2026-66145 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.