logo

Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution

ID: 257da24b-b2ec-551f-8d53-a9f1aeeb6e66

STIX ID: report--257da24b-b2ec-551f-8d53-a9f1aeeb6e66

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

Multiple high-severity vulnerabilities were identified in SonicWall Global Management System (GMS), including unauthenticated remote code execution (CVE-2026-66145), unauthenticated and authenticated command injection (CVE-2026-66147, CVE-2026-66148), multiple XSS issues (CVE-2026-66146), insecure certificate validation (CVE-2026-66154), and insecure deserialization (CVE-2026-18634); exploitation could allow attackers to execute arbitrary code, escalate privileges, and modify or exfiltrate data depending on service account privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.