SonicWall Issues Critical Security Update for Outdated GMS Platform
SonicWall has released updates to address eight security vulnerabilities across two products, including critical remote code execution (RCE) flaws affecting its discontinued Global Management System (GMS) platform.
Critical Remote Code Execution Flaws
SonicWall disclosed fixes for six issues in GMS, a centralized management, monitoring, and reporting tool that was decommissioned in October 2025. Two of the vulnerabilities, CVE-2026-66147 (CVSS score 9.4) and CVE-2026-66145 (CVSS score 9.1), require immediate attention due to their potential for remote, unauthenticated exploitation.
CVE-2026-66147 and CVE-2026-66145
CVE-2026-66147 involves a command injection vulnerability in the GMS Dispatcher Service, which could be triggered through maliciously crafted requests. This flaw allows attackers to execute arbitrary code on affected systems. CVE-2026-66145 is an RCE vulnerability that enables unauthorized data disclosure and arbitrary file writes via a zipslip attack vector. Both issues impact GMS versions 9.5.1 and earlier, including the Virtual Appliance and Windows editions. The vulnerabilities were resolved in version 9.5.2 of the software.
Additional High-Severity Issues
The update also includes fixes for two high-severity issues related to insufficient certificate validation and insecure handling of serialized objects. These flaws could lead to unauthorized modifications and actions within the system.
Security Product Vulnerabilities
In addition, SonicWall addressed two high-severity code injection vulnerabilities, CVE-2026-66149 and CVE-2026-66150, in its Security product. These flaws could allow attackers to execute operating system commands with root privileges. The affected systems include ES Appliance models 5000, 5050, 7000, 7050, 9000, as well as VMware and Hyper-V environments. The vulnerabilities were resolved in Security version 10.0.36.
Recommendations and Advisories
SonicWall has stated there is no evidence that any of the disclosed vulnerabilities have been actively exploited in real-world attacks. However, the company strongly advises users to apply the patches promptly to mitigate potential risks. Further details about the updates are available in SonicWall’s official security advisories.
