SonicWall GMS RCEs Hit Retired Management Platform

SonicWall fixed eight flaws across Global Management System (GMS) and Email Security, including two critical unauthenticated remote code execution bugs in GMS 9.5.1 and earlier. The company says the issues are resolved in GMS 9.5.2 and has no evidence of in-the-wild exploitation. One flaw lets a crafted request reach the GMS Dispatcher Service and run commands. The other abuses ZIP handling, where a malicious archive can write files where it should not and lead to arbitrary code execution and sensitive data disclosure. Because GMS is the central management, monitoring, and reporting layer, a hit there can expose more than one appliance. The risk sits with lingering GMS Virtual Appliance and GMS for Windows deployments, especially where operators still rely on a retired platform they may assume is out of reach. If GMS still anchors device administration in your environment, a remote compromise can put the management plane and the data it aggregates on the line.

Part of the PlainSec briefing for 2026-08-12

Editions

Sources