SonicWallCVE-2026-66154
SonicWall GMS: improper certificate validation
High8.3CVE-2026-66154 · Published Aug 11, 2026 · updated Aug 28, 2026
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GMS Product | <= 9.5.1 and earlier versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-295
More SonicWall advisories
All SonicWall| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SonicWall GMS: command injection | Critical9.4 | No fix yet |
| Aug 11 | SonicWall GMS: command injection | Medium6.3 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall Email Security: code injection | High7.8 | No fix yet |
| Aug 11 | SonicWall GMS: unsafe deserialization | High8.4 | No fix yet |
| Aug 11 | SonicWall GMS: remote code execution | Critical9.1 | No fix yet |