Patch released Global Management System rce Email Security SonicWall
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
CVE Tools coverage
SonicWall has released patches for eight vulnerabilities affecting its Global Management System (GMS) and Email Security platforms, addressing critical remote code execution risks. Notably, CVE-2026-66147 (CVSS 9.4) and CVE-2026-66145 (CVSS 9.1) in GMS allow unauthenticated attackers to execute arbitrary code via command injection and zipslip vulnerabilities, respectively. While GMS was discontinued in October 2025, updates for versions 9.5.1 and earlier are available in release 9.5.2. Additionally, two high-severity code injection flaws in Email Security appliances were resolved in version 10.0.36.