Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution
ID: 257da24b-b2ec-551f-8d53-a9f1aeeb6e66
STIX ID: report--257da24b-b2ec-551f-8d53-a9f1aeeb6e66
Feed Name: CISecurity.org Advisories
Multiple high-severity vulnerabilities were identified in SonicWall Global Management System (GMS), including unauthenticated remote code execution (CVE-2026-66145), unauthenticated and authenticated command injection (CVE-2026-66147, CVE-2026-66148), multiple XSS issues (CVE-2026-66146), insecure certificate validation (CVE-2026-66154), and insecure deserialization (CVE-2026-18634); exploitation could allow attackers to execute arbitrary code, escalate privileges, and modify or exfiltrate data depending on service account privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
