Skip to content
SonicWallCVE-2026-66147

SonicWall GMS: command injection

Critical9.4CVE-2026-66147 · Published Aug 11, 2026 · updated Aug 28, 2026

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

SonicWall advisory

Affected versions

PackageAffectedFixed in
GMS
Product
<= 9.5.1 and earlier versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-94

More SonicWall advisories

All SonicWall
Advisory
SonicWall GMS: command injection
Medium6.3Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall GMS: improper certificate validation
High8.3Aug 11
SonicWall GMS: unsafe deserialization
High8.4Aug 11
SonicWall GMS: remote code execution
Critical9.1Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.