CVE-2026-66147
CVSS 9.4 CRITICAL: an unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and…
Vulnerabilities · 47 days ago
SonicWall fixed eight flaws across Global Management System (GMS) and Email Security, including two critical unauthenticated remote code execution bugs in GMS 9.5.1 and earlier. The company says the issues are resolved in GMS 9.5.2 and has no evidence of in-the-wild exploitation.
One flaw lets a crafted request reach the GMS Dispatcher Service and run commands. The other abuses ZIP handling, where a malicious archive can write files where it should not and lead to arbitrary code execution and sensitive data disclosure. Because GMS is the central management, monitoring, and reporting layer, a hit there can expose more than one appliance.
The risk sits with lingering GMS Virtual Appliance and GMS for Windows deployments, especially where operators still rely on a retired platform they may assume is out of reach. If GMS still anchors device administration in your environment, a remote compromise can put the management plane and the data it aggregates on the line.
CVSS 9.4 CRITICAL: an unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and…
CVSS 9.1 CRITICAL: an unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier…
4 sources covering this story
Risolte vulnerabilità in prodotti SonicWall
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 8 vulnerabilità, di cui 2 con gravità “critica” e 4 con gravità "alta", che interessano i prodotti Email Security e GMS.
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
Zero Day Initiative Advisories
SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability
SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security.
Zero Day Initiative Advisories
SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability
SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance.
Zero Day Initiative Advisories
SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability
SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security.
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
Part of the PlainSec briefing for 2026-08-13