External risk intelligence

GMS Zip Slip Vulnerability Allows Remote Code Execution and Data Disclosure

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-66145

The vulnerability affects GMS (Global Management System), which is typically deployed as an internet-facing or edge-accessible management gateway for network appliances. Because it is designed to provide centralized remote management and control, it is commonly exposed to the internet or accessible via wide-area network boundaries in standard deployment patterns.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated remote code execution flaw has been identified in GMS, a system used for managing network devices. This vulnerability could allow attackers to access sensitive information or modify files on affected systems. The primary concern is to confirm if your organization utilizes this specific technology and is therefore exposed.

  • Unauthenticated code execution in management system.
  • Critical flaw impacts system integrity and data confidentiality.
  • Confirm relevance to your network infrastructure.

Attack Path

How an attacker could exploit the issue

An attacker can remotely exploit this vulnerability without authentication by sending a specially crafted zip archive to a vulnerable GMS system. This can lead to the attacker reading sensitive information and writing arbitrary files on the system.

  • No authentication required.
  • Triggered by a malicious zip archive.
  • Risk of sensitive data exposure and file writes.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to access sensitive data and write arbitrary files on the affected system. This could occur when the system is exposed to the network and processed a specially crafted zip file.

  • Sensitive system data.
  • Via crafted zip file.
  • Unauthorized file access.

Operational Fix

Recommended remediation, mitigation, and detection steps

GMS ownership likely falls to the platform or infrastructure teams responsible for the Global Management System, with support from network and security teams for exposure assessment. The initial practical step is to inventory all GMS instances, confirm their accessibility, and identify the business-critical systems to prioritize remediation efforts.

  • Platform or infrastructure teams own this issue.
  • Verify GMS instance exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GMS 9.5.1?

GMS (Global Management System) is a centralized platform used to manage, monitor, and configure network appliances. It serves as a command hub for infrastructure, allowing administrators to oversee multiple devices from a single point. It is not an end-user workstation application but a critical management gateway for network operations.

How does this CVE-2026-66145 vulnerability work?

This flaw is classified as CWE-94, which involves improper control of code generation. In this case, the system incorrectly handles zip file extraction. By using a 'zip slip' technique, an attacker can manipulate file paths within a malicious archive to write files outside of the intended directory, enabling them to execute arbitrary code or access sensitive data.

Do I need to be authenticated to trigger CVE-2026-66145?

No, authentication is not required to trigger this vulnerability. An attacker can initiate the attack remotely by sending a specially crafted zip archive to the system. Normal system operations that do not involve processing or extracting untrusted or unvalidated zip archives are not the trigger for this specific file-write flaw.

Why is this CVE considered relevant for my network?

Halo Surface Signal indicates that GMS is typically deployed as an internet-facing or edge-accessible management gateway. Because its purpose is to provide centralized control, these systems are often placed at network boundaries, making them highly visible to remote attackers who scan for management interfaces on the open internet.

What are the first steps to address this flaw?

Start by conducting an inventory of all GMS instances within your environment. Work with your infrastructure or platform teams to determine which instances are accessible via the network and prioritize those that are business-critical. Once identified, confirm your exposure level to ensure you can apply the necessary remediation measures as they become available.

References