SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
PatchGlobal Management SystemEmail SecurityOur summary
SonicWall has released patches for eight vulnerabilities affecting its Global Management System (GMS) and Email Security platforms, addressing critical remote code execution risks. Notably, CVE-2026-66147 (CVSS 9.4) and CVE-2026-66145 (CVSS 9.1) in GMS allow unauthenticated attackers to execute arbitrary code via command injection and zipslip vulnerabilities, respectively. While GMS was discontinued in October 2025, updates for versions 9.5.1 and earlier are available in release 9.5.2. Additionally, two high-severity code injection flaws in Email Security appliances were resolved in version 10.0.36.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.