SonicWall has released patches for eight vulnerabilities affecting its Global Management System (GMS) and Email Security products, including critical flaws that could enable remote code execution. The most severe issues, tracked as CVE-2026-66147 and CVE-2026-66145, impact GMS 9.5.1 and earlier on both Windows and Linux. SonicWall said the GMS issues were fixed in version 9.5.2, while Email Security vulnerabilities were addressed in version 10.0.36.
CVE-2026-66147 is described as an unauthenticated command injection flaw in the GMS Dispatcher Service that can allow remote attackers to execute arbitrary code via crafted requests. CVE-2026-66145 affects the discontinued GMS platform and can allow unauthenticated attackers to achieve remote code execution, read sensitive data, and perform arbitrary file writes through a Zip Slip condition. SonicWall said it has no evidence of in-the-wild exploitation, but the vulnerabilities carry high technical impact and customers were urged to update promptly.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
As part of its August 12, 2026 patch announcement, SonicWall stated it had no evidence that the disclosed vulnerabilities had been exploited in the wild and urged customers to apply updates promptly.
On August 12, 2026, SonicWall announced patches for eight vulnerabilities across its GMS and Email Security products. The company fixed six GMS issues, including critical flaws CVE-2026-66145 and CVE-2026-66147 in GMS version 9.5.2, and patched Email Security command injection bugs CVE-2026-66149 and CVE-2026-66150 in version 10.0.36.
On August 11, 2026, the CVE record for CVE-2026-66147 was newly received by PSIRT@sonicwall.com and updated with affected-product details, description, CVSS data, and a SonicWall PSIRT advisory reference. The issue is an unauthenticated command injection flaw in the GMS Dispatcher Service that can lead to remote code execution on SonicWall GMS 9.5.1 and earlier for Windows and Linux.
On August 11, 2026, the CVE record for CVE-2026-66145 was newly received by PSIRT@sonicwall.com and updated with affected-product details, vulnerability description, CVSS data, and a SonicWall PSIRT advisory reference. The flaw affects SonicWall GMS 9.5.1 and earlier on Windows and Linux and can enable unauthenticated remote code execution, sensitive-data access, and arbitrary file write via Zip Slip.
SecurityWeek reported that SonicWall retired its Global Management System (GMS) platform in October 2025. The later-disclosed GMS vulnerabilities affected this discontinued product line.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourceacn.gov.it
Open sourcesecurityweek.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcepsirt.global.sonicwall.com
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.