SonicWall has released patches for multiple security flaws across two of its products, including critical vulnerabilities that could allow remote attackers to run code. The updates matter even more because one affected platform—its Global Management System (GMS)—was retired in October 2025.
According to SonicWall’s advisory, the company addressed eight vulnerabilities in total, with the most urgent risks tied to GMS. SonicWall also issued fixes for two high-severity code injection bugs in Email Security.
What SonicWall patched in the discontinued GMS platform
SonicWall rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform. The platform is discontinued, having been retired in October 2025, but the company still recommends updating because devices that remain deployed can be exposed.
The vulnerabilities impact GMS versions 9.5.1 and earlier, covering both the Virtual Appliance and Windows variants. SonicWall resolved the issues in GMS version 9.5.2.
Critical remote code execution risks (CVE-2026-66147 and CVE-2026-66145)
Two of the GMS vulnerabilities carry especially high risk ratings and require prompt attention. SonicWall highlights these as critical-severity issues that could enable remote, unauthenticated attackers to execute arbitrary code.
The first is CVE-2026-66147 (CVSS 9.4). SonicWall describes it as a command injection weakness in the GMS Dispatcher Service. Attackers may be able to exploit it by sending specially crafted requests that trigger command execution.
The second is CVE-2026-66145 (CVSS 9.1). SonicWall reports this as a remote code execution vulnerability that can also lead to sensitive data disclosure and arbitrary file write through a zip-slip style path traversal scenario.
In practice, the combination of unauthenticated access and remote code execution makes these flaws particularly dangerous. Systems that expose the affected service without appropriate protections may be at higher risk than internal-only deployments.
Other high-severity issues addressed in GMS
Beyond the two highlighted critical flaws, SonicWall also fixed additional high-severity problems in GMS version 9.5.2. The advisory notes issues including insufficient certificate validation and insecure handling of serialized objects.
These weaknesses can potentially allow unauthorized changes and actions, depending on how the affected components are used and what security controls are in place. Even if an organization does not expose GMS broadly to the internet, internal users and adjacent systems can still become an attack path.
Required update path for GMS users
SonicWall’s remediation guidance is straightforward: update GMS from version 9.5.1 or earlier to version 9.5.2 to resolve the reported vulnerabilities.
If you manage GMS in a virtual environment or run it on Windows, confirm your current software release number and validate that your update process completes successfully. Because the platform has been retired, it is easy for organizations to fall behind on maintenance schedules—so it’s worth double-checking change logs and patch deployment records.
Email Security patches for code injection flaws
Alongside the GMS fixes, SonicWall also published updates for two high-severity code injection vulnerabilities in its Email Security product. These issues could allow OS command execution with root privileges, which substantially increases potential impact if the flaws are reachable.
The affected components include ES Appliance models 5000, 5050, 7000, 7050, and 9000, as well as environments running on VMware and Hyper-V. SonicWall states that the vulnerabilities were resolved in Email Security version 10.0.36.
While SonicWall does not describe exploitation details in the brief advisory summary, it identifies the flaws as CVE-2026-66149 and CVE-2026-66150. Since root-level command execution is involved, organizations should treat these as urgent and prioritize the upgrade.
No evidence of exploitation reported, but patch quicklySonicWall says it has no evidence that these vulnerabilities have been exploited in the wild. Even so, the company urges users to apply the patches as soon as possible.
This recommendation is especially important for the discontinued GMS platform. Retirement does not eliminate risk; it mainly increases the chance that some deployments remain unpatched simply because maintenance attention shifts elsewhere.
How to act on these advisories
If you operate any of the affected products, consider the following practical steps:
- Check versions of GMS and Email Security across appliances and virtual instances.
- Plan and apply updates to reach GMS 9.5.2 and Email Security 10.0.36.
- Validate exposure to relevant services, especially components described in the advisories (such as the GMS Dispatcher Service).
- Review certificate and serialization-related settings where applicable, since those were part of the fixed risk areas.
For additional details, SonicWall directs users to its security advisories page. Organizations should rely on the official guidance when confirming affected configurations and upgrade steps.
Why patching matters after product retirement
Discontinued products can create a false sense of safety. Teams may stop routine patch monitoring because they assume retirement reduces the likelihood of ongoing updates or new threats. However, vulnerabilities can still be targeted, and remote exploitation paths—like those described for GMS—make timely remediation critical.
By releasing patches for a retired platform and addressing remote code execution and other high-severity issues, SonicWall reinforces a broader lesson for security operations: asset inventory and patch discipline must stay active, even when a product lifecycle ends.
Conclusion
SonicWall has issued patches addressing eight vulnerabilities across GMS and Email Security. The most urgent fixes are for critical remote code execution risks in GMS, including unauthenticated command injection and RCE paths tied to specific CVEs. SonicWall recommends updating GMS to 9.5.2 and Email Security to 10.0.36, noting that there is no evidence of active exploitation but emphasizing that users should patch promptly.
