TL;DR
SonicWall disclosed critical flaws in its GMS and Email Security products on August 11, 2026. The most severe is a SonicWall GMS vulnerability, CVE-2026-66147, scoring CVSS 9.4. It allows unauthenticated remote code execution on affected servers.
- Product: SonicWall (2 products)
- Vulnerabilities: 3 flaws (CVE-2026-66147, CVE-2026-66145, CVE-2026-66149)
- Highest severity: 9.4 (Critical · CVSSv3)
- Worst impact: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service...
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-66147 | 9.4 | CWE-94 | — | Not exploited |
| CVE-2026-66145 | 9.1 | CWE-94 | — | Not exploited |
| CVE-2026-66149 | 7.8 | CWE-94 | — | Not exploited |
Why This SonicWall GMS Vulnerability Matters
GMS, or Global Management System, is the central console for managing SonicWall firewalls. A compromise there can expose an entire fleet of devices. Because two of the flaws need no login, internet-facing servers face real risk.
How the Attacks Work
The GMS advisory covers four bugs. CVE-2026-66147 is an unauthenticated command injection in the GMS Dispatcher Service. Attackers reach code execution through specially crafted requests.
A second unauthenticated flaw, CVE-2026-66145 (CVSS 9.1), abuses a zipslip weakness. It lets an attacker read sensitive data and write arbitrary files. The set also includes cross-site scripting and privilege escalation bugs.
Email Security Flaws
A separate advisory covers SonicWall Email Security. CVE-2026-66149 and CVE-2026-66150 (both CVSS 7.8) allow code injection through the restricted CLI. However, both require an authenticated attacker.
Affected Versions
The GMS flaws affect Virtual Appliance and Windows builds 9.5.1 and earlier. The Email Security bugs affect version 10.0.35.8405 and earlier. SonicWall confirmed its Analytics products are not affected.
Patch and Mitigation Steps
No workarounds exist, so patching is the only fix. Upgrade GMS to version 9.5.2 and Email Security to 10.0.36 or later. Review the official advisories for GMS (SNWLID-2026-0011) and Email Security (SNWLID-2026-0012).
SonicWall reports no evidence that attackers exploit these flaws in the wild. Even so, this SonicWall GMS vulnerability set deserves fast action given the unauthenticated access.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.