SonicWall Patches Critical RCE and Data Disclosure Vulnerabilities in Discontinued GMS Platform
SonicWall has released patches for critical vulnerabilities, including remote code execution and data disclosure flaws, in its discontinued Global Management System (GMS) platform.

SonicWall has issued security advisories and released patches for eight vulnerabilities affecting its Global Management System (GMS) platform, a product that reached its end-of-life in October 2025. Despite the discontinuation, users are strongly urged to update their GMS installations to address critical security flaws that could expose sensitive data and allow for arbitrary code execution.
Two of the most severe vulnerabilities, CVE-2026-66147 and CVE-2026-66145, are rated with CVSS scores of 9.4 and 9.1, respectively. CVE-2026-66147 is a command injection vulnerability within the GMS Dispatcher Service, exploitable through crafted network requests. CVE-2026-66145 is an arbitrary code execution flaw that also leads to sensitive data disclosure and arbitrary file write capabilities via a zipslip vulnerability.
These critical vulnerabilities impact GMS versions 9.5.1 and earlier, including both the Virtual Appliance and Windows installations. SonicWall has resolved these issues in version 9.5.2 of the GMS software. The update also addresses other high-severity defects, such as insufficient certificate validation and insecure handling of serialized objects, which could permit unauthorized system modifications and actions.
In addition to the GMS vulnerabilities, SonicWall also released patches for two high-severity code injection flaws (CVE-2026-66149 and CVE-2026-66150) in its Email Security (ES) product. These flaws could allow attackers to execute operating system commands with root privileges.
The affected Email Security versions include ES Appliance 5000, 5050, 7000, 7050, 9000, as well as VMware and Hyper-V deployments. These issues have been remediated in Email Security version 10.0.36.
While SonicWall has stated that there is no evidence of these specific vulnerabilities being exploited in the wild, the company emphasizes the importance of applying the patches promptly. Further technical details and guidance can be found on SonicWall's official security advisories page.
The patching of vulnerabilities in a discontinued product highlights the ongoing security challenges faced by organizations that continue to use end-of-life software. It underscores the need for diligent asset management and timely migration to supported platforms to mitigate potential risks from newly discovered exploits.