Vulnerabilities

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.

SonicWall vulnerability

SonicWall on Tuesday announced patches for eight vulnerabilities across two products, including critical-severity remote code execution (RCE) bugs.

The cybersecurity firm rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform that was retired in October 2025.

Per SonicWall’s advisory, two of the flaws, namely CVE-2026-66147 (CVSS score of 9.4) and CVE-2026-66145 (CVSS score of 9.1), deserve special attention, as both could allow remote, unauthenticated attackers to execute arbitrary code.

The former is described as a command injection issue in the GMS Dispatcher Service that can be exploited via crafted requests. The latter is an RCE bug leading to sensitive data disclosure and arbitrary file write via zipslip.

Impacting the 9.5.1 and earlier versions of GMS (Virtual Appliance and Windows), the vulnerabilities were resolved in version 9.5.2 of the software.

The update also addresses high-severity insufficient certificate validation and insecure handling of serialized objects bugs that could lead to unauthorized changes and actions.

Advertisement. Scroll to continue reading.

On Tuesday, SonicWall also rolled out fixes for two high-severity code injection flaws (CVE-2026-66149 and CVE-2026-66150) in Email Security that could lead to OS command execution with root privileges.

Affecting ES Appliance 5000, 5050, 7000, 7050, 9000, VMware and Hyper-V, the two issues were resolved in Email Security version 10.0.36.

SonicWall says it has no evidence that any of these vulnerabilities have been exploited in the wild but urges users to apply the patches as soon as possible. Additional information can be found on SonicWall’s security advisories page.

Related: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Related: Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Related: Zoom Patches Zero-Click Code Execution Vulnerability

Related Content

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Artificial Intelligence

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Email Security

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Vulnerabilities

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

Vulnerabilities

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

Vulnerabilities

The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.

Vulnerabilities

The browser update resolves several critical-severity memory safety and memory corruption flaws.

Vulnerabilities

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version