SonicWall fixes critical GMS flaws, patches Email Security

SonicWall issued patches for eight vulnerabilities across GMS and Email Security, addressing two critical remote‑code‑execution flaws in retired GMS and two high‑severity code‑injection bugs.
On Tuesday, SonicWall issued software updates that fix eight security flaws in its Global Management System (GMS) and Email Security products.
Two of the most severe GMS flaws are tracked as CVE-2026-66147 (CVSS 9.4) and CVE-2026-66145 (CVSS 9.1). CVE-2026-66147 is a command injection vulnerability in the GMS Dispatcher Service that can be triggered by crafted requests. CVE-2026-66145 involves a zipslip condition that can lead to sensitive data disclosure and arbitrary file writes.
The GMS defects affect version 9.5.1 and earlier for both the Virtual Appliance and Windows editions and are fixed in GMS version 9.5.2. The update also addresses high-severity issues related to insufficient certificate validation and insecure handling of serialized objects that could permit unauthorized changes.
SonicWall also patched two high-severity code-injection vulnerabilities in Email Security, listed as CVE-2026-66149 and CVE-2026-66150. Both could allow operating-system command execution with root privileges. Affected platforms include ES Appliance models 5000, 5050, 7000, 7050 and 9000, as well as VMware and Hyper-V deployments; the fixes are included in Email Security version 10.0.36.
GMS is SonicWall’s centralized management, monitoring and reporting platform that the company retired in October 2025. The vendor released the GMS update so organizations still running legacy appliances or Windows instances can upgrade to 9.5.2.
The advisory notes there is no evidence the vulnerabilities have been exploited in the wild and urges administrators to apply the updates promptly. SonicWall’s security advisories page provides technical details and remediation guidance.
SonicWall recommended that administrators review release notes, verify backups and test patches in nonproduction environments when feasible. The advisory also recommends restricting management access to trusted networks and monitoring logs for suspicious activity until fixes are applied.








