SONICWALL has released patches for eight vulnerabilities in its products, particularly focusing on two critical remote code execution (RCE) flaws in the Global Management System (GMS) which could allow unauthenticated attackers to execute arbitrary code. The vulnerabilities, identified as CVE-2026-66147 and CVE-2026-66145, have CVSS scores of 9.4 and 9.1, respectively, and were addressed in GMS version 9.5.2.
Additionally, two high-severity code injection vulnerabilities were patched in Email Security products, affecting various appliance models. Although SonicWall reports no known exploitation of these flaws, users are urged to apply the patches promptly. Further details can be found in SonicWall's security advisories.