Product Notice: SonicWall GMS Security Affected By Multiple Vulnerabilities

1786446350

Overview

  • CVE-2026-66145: GMS Code Injection Vulnerability – CVSS Score: 9.1 (Critical)*
  • CVE-2026-66146: GMS Multiple Cross-Site Scripting (XSS) Vulnerabilities – CVSS Score: 5.5 (Medium)
  • CVE-2026-66147: GMS Unauthenticated Command Injection in Dispatcher Service – CVSS Score: 9.4 (Critical)
  • CVE-2026-66148: GMS Local Privilege Escalation via Authenticated Command Injection – CVSS Score: 6.3 (Medium)
  • CVE-2026-66154: GMS Weak Certificate Verification Leading to User Compromise via MitM – CVSS Score: 8.3 (High)
  • CVE-2026-18634: GMS Local Privilege Escalation via Deserialization – CVSS Score: 8.4 (High)

This issue affects SonicWall Global Management System (GMS) – Virtual Appliance and Windows running version 9.5.1-SP1 and earlier.

SonicWall recommends upgrading to the fixed version as soon as possible. The latest release is available for download on mysonicwall.com.

Product Impact

Please review the table below to see the products and their versions that are impacted:

Impacted Product(s)

Impacted Version(s)

GMS – Virtual Appliance and Windows

9.5.1-SP1 and earlier versions

Remediation

Impacted Product(s)

Impacted Version(s)

Fixed Version

GMS – Virtual Appliance and Windows

9.5.1-SP1 and earlier versions

9.5.2 and higher versions

SonicWall strongly advises all GMS customers to upgrade to version 9.5.2 or higher as soon as possible via mysonicwall.com.

Related Information

  • Previous Alert
    Product Notice: SonicWall Email Security Affected by Multiple Vulnerabilities
    Read More