SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

https://www.securityweek.com/wp-content/uploads/2025/08/SonicWall.jpg

SonicWall on Tuesday announced patches for eight vulnerabilities across two products, including critical-severity remote code execution (RCE) bugs.

The cybersecurity firm rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform that was retired in October 2025.

Per SonicWall’s advisory, two of the flaws, namely CVE-2026-66147 (CVSS score of 9.4) and CVE-2026-66145 (CVSS score of 9.1), deserve special attention, as both could allow remote, unauthenticated attackers to execute arbitrary code.

The former is described as a command injection issue in the GMS Dispatcher Service that can be exploited via crafted requests. The latter is an RCE bug leading to sensitive data disclosure and arbitrary file write via zipslip.

Impacting the 9.5.1 and earlier versions of GMS (Virtual Appliance and Windows), the vulnerabilities were resolved in version 9.5.2 of the software.

The update also addresses high-severity insufficient certificate validation and insecure...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more