Skip to content
SonicWallCVE-2026-66149

SonicWall Email Security: code injection

High7.8CVE-2026-66149 · Published Aug 11, 2026 · updated Aug 28, 2026

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

SonicWall advisory

Affected versions

PackageAffectedFixed in
Email Security
Product
<= 10.0.35.8405 and earlier versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-94

More SonicWall advisories

All SonicWall
Advisory
SonicWall GMS: command injection
Critical9.4Aug 11
SonicWall GMS: command injection
Medium6.3Aug 11
SonicWall Email Security: code injection
High7.8Aug 11
SonicWall GMS: improper certificate validation
High8.3Aug 11
SonicWall GMS: unsafe deserialization
High8.4Aug 11
SonicWall GMS: remote code execution
Critical9.1Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.