SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

Key points
- SonicWall released patches for eight security flaws across two products on Tuesday, including two rated critically dangerous.
- CVE-2026-66147 (danger score 9.4 out of 10) and CVE-2026-66145 (9.1) both allow a remote attacker with no password to run malicious code on affected systems.
- The flawed product, Global Management System (GMS), was retired by SonicWall in October 2025, yet thousands of organisations may still run it.
- Two additional high-severity flaws in SonicWall Email Security could give attackers full administrative control over mail servers.
- SonicWall says none of the eight flaws have been exploited yet, but it is urging customers to patch immediately.
SonicWall makes networking and security hardware used by businesses, schools, and government offices to protect their internet connections. On Tuesday the company quietly disclosed eight security flaws and shipped fixes, first reported by SecurityWeek.
The headline problem involves its Global Management System, known as GMS. Think of GMS as a control panel: it lets IT staff manage dozens of SonicWall devices from one screen. Retiring a product means the maker stops selling it, but organisations that still run it keep using it in production until they migrate away.
How bad are these flaws?
Bad enough that two of them score above 9 on a 10-point industry scale used to rank severity. Both allow what security researchers call remote code execution, meaning a criminal can send commands to the system across the internet and the machine will carry them out, no login required.
CVE-2026-66147, rated 9.4, lets an attacker inject commands through a part of GMS called the Dispatcher Service by sending specially crafted network requests. CVE-2026-66145, rated 9.1, exploits a technique called zipslip, where a malicious compressed file tricks the software into writing files wherever the attacker chooses, leaking sensitive data in the process.
Both affect GMS versions 9.5.1 and earlier, on both the virtual and Windows editions. Version 9.5.2 fixes them.
| Product | Flaw | Danger score | Fixed in |
|---|---|---|---|
| GMS | CVE-2026-66147 (command injection) | 9.4 | 9.5.2 |
| GMS | CVE-2026-66145 (zipslip RCE) | 9.1 | 9.5.2 |
| GMS | Certificate validation flaw | High | 9.5.2 |
| GMS | Insecure serialised objects | High | 9.5.2 |
| Email Security | CVE-2026-66149 (code injection) | High | 10.0.36 |
| Email Security | CVE-2026-66150 (code injection) | High | 10.0.36 |
The failure mode here is straightforward: an attacker finds an internet-exposed GMS panel, sends a crafted request, and owns the control plane for every SonicWall device that panel manages. One door, many rooms behind it.
Should ordinary users be worried?
Directly, no. GMS sits inside corporate and institutional networks. But if a business you rely on, a bank, a clinic, a local council, runs unpatched SonicWall gear, criminals with full control of that infrastructure can read traffic, pivot deeper into internal systems, and set up future attacks.
SonicWall also patched two high-severity injection flaws, CVE-2026-66149 and CVE-2026-66150, in its Email Security appliances covering the ES 5000, 5050, 7000, 7050, 9000 and virtualised versions. Those bugs can give an attacker root privileges, meaning total control, over a mail server. Version 10.0.36 of Email Security closes both.
In practice, the clock starts ticking the moment these CVEs are public. Scanning tools that probe for vulnerable software get updated fast.
If your IT team manages SonicWall products, the update schedule is the only conversation that matters this week.



