SonicWall GMS hit by two critical unauthenticated RCE flaws affecting all versions through 9.5.1

SonicWall has disclosed two critical remote code execution vulnerabilities in its Global Management System (GMS) product, both exploitable without authentication. The flaws, published today by SecurityOnline, affect GMS version 9.5.1 and all earlier releases — a product widely deployed by managed service providers and enterprise IT teams to centrally manage SonicWall firewall estates.
What the vulnerabilities do
CVE-2026-66147, rated CVSS 9.4, is an unauthenticated command injection flaw in the GMS Dispatcher Service. A remote attacker can send a specially crafted request to the service and execute arbitrary commands on the underlying operating system — no credentials required. The vulnerability is classified under CWE-94 (Improper Control of Code Generation).
The second vulnerability, CVE-2026-66145, carries a CVSS score of 9.1 and is similarly described as an unauthenticated remote code execution flaw in the same product. The close proximity of the CVE numbers and the shared product suggest both issues were identified as part of the same security research effort or internal audit.
Why this is serious
GMS is not a firewall — it is the management plane that sits above firewalls. A compromise here means an attacker gains control over the entire network management infrastructure: firewall policies, VPN configurations, user access rules, and logging. That level of access could allow an adversary to silently reconfigure network defenses, open backdoors, or pivot deeper into an organization without triggering alerts on the managed firewalls themselves.
The unauthenticated nature of both exploits means attackers do not need stolen credentials to trigger them. Any GMS instance exposed to the internet — or reachable from a compromised network segment — is a viable target.
What to do
SonicWall has directed affected organizations to consult its PSIRT advisory portal at psirt.global.sonicwall.com for specific patching guidance and the target upgrade version. Administrators running GMS 9.5.1 or earlier should treat this as an emergency patch and prioritize upgrades. If immediate patching is not possible, restricting network access to the GMS management interface to trusted IP ranges is a critical interim step.
Organizations should also review GMS audit logs for any unusual dispatcher activity since July 24, 2026 — the date the CVEs were first reserved — as a precautionary measure against pre-patch exploitation.
Originally reported by SecurityOnline. Read the original article for additional details.
View original source