SonicWallCVE-2026-18634
SonicWall GMS: unsafe deserialization
High8.4CVE-2026-18634 · Published Aug 11, 2026 · updated Aug 28, 2026
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GMS Product | <= 9.5.1 and earlier versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-502
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: command injection | Critical9.4 | No fix yet |
| Aug 11 | SonicWall GMS: command injection | Medium6.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: improper certificate validation | High8.3 | No fix yet |
| Aug 11 | SonicWall GMS: remote code execution | Critical9.1 | No fix yet |