Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

0
Critical
Vulnerability
Published: 08/12/2026 (08/12/2026, 07:31:11 UTC)
Source: SecurityWeek

Description

SonicWall patched eight vulnerabilities including critical remote code execution flaws in its discontinued Global Management System (GMS) platform and high-severity code injection bugs in Email Security products. The critical GMS vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. These issues affect GMS versions 9.5.1 and earlier and were fixed in version 9.5.2. Email Security appliances were also updated to address code injection vulnerabilities that could lead to root-level command execution. SonicWall has not observed exploitation in the wild but urges immediate patching.

Affected software

Affected versions
<=9.5.1<10.0.36

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 07:41:23 UTC

Technical Analysis

SonicWall released patches for eight security vulnerabilities across two products: the discontinued Global Management System (GMS) and Email Security appliances. Two critical vulnerabilities in GMS (CVE-2026-66147 and CVE-2026-66145) allow unauthenticated remote code execution and sensitive data disclosure via command injection and zip slip attacks, respectively. These affect GMS Virtual Appliance and Windows versions 9.5.1 and earlier and were fixed in 9.5.2. Additional high-severity flaws include insufficient certificate validation and insecure serialized object handling. Email Security appliances (models 5000, 5050, 7000, 7050, 9000, VMware, Hyper-V) were patched for two high-severity code injection vulnerabilities (CVE-2026-66149 and CVE-2026-66150) that could lead to OS command execution with root privileges, fixed in version 10.0.36. SonicWall confirms no known exploitation but recommends prompt updates.

Potential Impact

Successful exploitation of the critical GMS vulnerabilities could allow unauthenticated attackers to remotely execute arbitrary code and access sensitive data, potentially compromising the management platform. The Email Security vulnerabilities could enable attackers to execute OS commands with root privileges, risking full system compromise. These impacts are severe given the elevated privileges and unauthenticated attack vectors.

Mitigation Recommendations

SonicWall has released official patches addressing these vulnerabilities: GMS users should upgrade to version 9.5.2 or later, and Email Security appliance users should update to version 10.0.36 or later. Immediate application of these patches is strongly recommended. There is no evidence of exploitation in the wild. Users should follow SonicWall’s official security advisories for detailed update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.85,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/sonicwall-patches-critical-vulnerabilities-in-discontinued-gms-platform/","fetched":true,"fetchedAt":"2026-08-12T07:41:14.040Z","wordCount":959}

Threat ID: 6a7c239abf8831d5392e20e1

Added to database: 08/12/2026, 07:41:14 UTC

Last enriched: 08/12/2026, 07:41:23 UTC

Last updated: 08/12/2026, 10:36:02 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses