AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66146

MEDIUM · CVSS 6.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Multiple Cross-Site Scripting (XSS) vulnerabilities in Java's GMS 9.5.1 and earlier versions enable remote attackers to execute malicious JavaScript in users' browsers, potentially leading to unauthorized actions or data exposure. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation, particularly those handling sensitive user data or web applications.

CVE
CVE-2026-66146
Severity
MEDIUM
CVSS
6.1
EPSS
0.26%
Java

Original NVD Description

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.