SonicWall disclosed multiple vulnerabilities affecting Email Security and GMS, prompting a Canadian Centre for Cyber Security advisory urging administrators to review vendor guidance and apply updates. The affected products include SonicWall Email Security 10.0.35.8405 and earlier and SonicWall GMS 9.5.1 and earlier. The Cyber Centre said the issues were current as of August 11 and advised organizations to deploy fixes as they become available.
For SonicWall Email Security, SonicWall identified two authenticated code injection flaws, CVE-2026-66149 and CVE-2026-66150, each rated CVSS 7.8, that could let a user with access to the restricted CLI inject arbitrary OS commands as root through the netmask and SNMP vectors. Separately, CVE-2026-66154 affects SonicWall GMS on Linux and stems from insufficient certificate validation in a privileged communication workflow, creating a man-in-the-middle path to unauthorized changes under controlled network conditions. SonicWall said it had no evidence of in-the-wild exploitation for the Email Security flaws and directed customers to upgrade to fixed releases.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published alert AV26-809 stating that, as of August 11, 2026, SonicWall Email Security 10.0.35.8405 and earlier and SonicWall GMS 9.5.1 and earlier are affected by vulnerabilities. The notice advised users and administrators to review the linked advisories and apply updates as they become available.
A CVE record for CVE-2026-66154 was received and modified on August 11, 2026, describing an insufficient certificate validation vulnerability affecting SonicWall GMS 9.5.1 and earlier on Linux. The entry references SonicWall advisory SNWLID-2026-0011 and notes the flaw could permit unauthorized changes under man-in-the-middle conditions.
SonicWall published advisory SNWLID-2026-0012 disclosing CVE-2026-66149 and CVE-2026-66150 in SonicWall Email Security. The vulnerabilities allow an authenticated attacker with restricted CLI access to inject arbitrary OS commands as root via the netmask and SNMP vectors, and SonicWall said there was no evidence of in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourcecvefeed.io
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.