SonicWall has released security fixes for critical flaws that could let attackers break into its discontinued Global Management System and run commands on Email Security appliances. In GMS 9.5.1 and earlier, CVE-2026-66147 and CVE-2026-66145 allow remote unauthenticated code execution, with the latter also enabling sensitive-data disclosure and arbitrary file write via Zip Slip. SonicWall fixed six GMS issues in version 9.5.2 and two Email Security command-injection flaws, CVE-2026-66149 and CVE-2026-66150, in Email Security 10.0.36.
Why it matters: Organizations still running SonicWall GMS or Email Security could be exposed to full system compromise without a valid login, so this is an update-now issue. GMS is especially risky because it is a retired product, meaning lagging or abandoned deployments may remain exposed on the internet.
Ionut Arghire
2026.08.12
100% relevant
This article establishes a distinct patch story centered on newly disclosed SonicWall CVEs in GMS and Email Security, not the previously tracked SonicWall SSL-VPN MFA bypass event.
← Back to all stories