
SONICWALL has released patches for two critical remote code execution vulnerabilities affecting its Global Management System, tracked as CVE-2026-66147 and CVE-2026-66145. The flaws, rated 9.4 and 9.1 on the CVSS scale, could allow an unauthenticated attacker to execute arbitrary code on vulnerable appliances. The updates also address several additional issues in SonicWall’s Email Security products, marking a rare patch release for a platform that has been declared end of life. Further information is available in the vendor’s advisory SNWLID-2026-0011.
CVE-2026-66147 resides in the GMS web interface where improper validation of user‑supplied data permits remote code execution without authentication. An attacker can send a specially crafted HTTP request that triggers a deserialization flaw, leading to the execution of commands with the privileges of the GMS service account. CVE-2026-66145, meanwhile, stems from an insecure default configuration in the GMS API that allows unauthenticated file upload and subsequent remote code execution. Both flaws are mitigated in GMS version 9.5.2, which includes input validation improvements and stricter API controls.
Alongside the GMS fixes, SonicWall also addressed two high‑severity code injection vulnerabilities in its Email Security products. These flaws affect releases earlier than version 10.0.35.8405 and could be triggered by specially crafted SMTP messages that bypass authentication mechanisms. While the advisory does not disclose separate CVE identifiers for the Email Security issues, the patches are bundled in the same update cycle. SonicWall’s statement confirms that, to date, there has been no detected exploitation of any of the eight vulnerabilities covered by the advisory.
Despite the absence of observed attacks, the high CVSS scores indicate that any internet‑facing GMS or Email Security interface presents a significant risk. Threat intelligence feeds have not linked the flaws to any specific ransomware groups or nation‑state actors, but the ease of unauthenticated exploitation makes them attractive targets for opportunistic scanning campaigns. Organisations that still rely on the legacy GMS for centralized logging should treat the update as urgent, given that the platform no longer receives regular feature updates.
Administrators should immediately download the GMS 9.5.2 virtual appliance or Windows installer from the SonicWall support portal and apply it to all management nodes. For Email Security, upgrading to the latest build available on the same portal will close the injection vectors. Where immediate patching is not feasible, restricting access to the GMS and Email Security management ports to trusted IP addresses and enabling multi‑factor authentication for administrative accounts can reduce exposure. Additionally, reviewing firewall logs for unusual POST or SMTP traffic can help identify attempted exploitation before a breach occurs.
SonicWall advises customers to subscribe to its security mailing list and to check the PSIRT page regularly for any future advisories related to GMS or Email Security. Staying current with patches and maintaining a disciplined patch management schedule remain the most effective defences against vulnerabilities of this severity.