CVE-2026-66147
CVSS 9.4 CRITICAL: an unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and…
Vulnerabilities & Exploits
SonicWall fixed eight flaws across Global Management System (GMS) and Email Security, including two critical unauthenticated remote code execution bugs in GMS 9.5.1 and earlier. The company says the issues are resolved in GMS 9.5.2 and has no evidence of in-the-wild exploitation.
One flaw lets a crafted request reach the GMS Dispatcher Service and run commands. The other abuses ZIP handling, where a malicious archive can write files where it should not and lead to arbitrary code execution and sensitive data disclosure. Because GMS is the central management, monitoring, and reporting layer, a hit there can expose more than one appliance.
The risk sits with lingering GMS Virtual Appliance and GMS for Windows deployments, especially where operators still rely on a retired platform they may assume is out of reach. If GMS still anchors device administration in your environment, a remote compromise can put the management plane and the data it aggregates on the line.
4 sources · Aug 12
CVSS 9.4 CRITICAL: an unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and…
CVSS 9.1 CRITICAL: an unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier…
CSIRT Italia / ACN
Risolte vulnerabilità in prodotti SonicWall
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 8 vulnerabilità, di cui 2 con gravità “critica” e 4 con gravità "alta", che interessano i prodotti Email Security e GMS.
originalSecurityWeek
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
originalZero Day Initiative Advisories
SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security.
originalPart of the PlainSec briefing for 2026-08-13
Every edition of this story: SonicWall GMS RCEs Hit Retired Management Platform