Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
9.4
CVE-2026-66147PATCHED
sonicwall · gms

CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier

Description

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

Affected Products

VendorProductVersions
sonicwallgms9.5.1 and earlier versions

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallgmscert_advisory90%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories11h ago
[NEU] [hoch] SonicWall GMS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR20h ago
Multiples vulnérabilités dans les produits SonicWall (12 août 2026)
→ No new info (linked only)
Tier C
VulDB23h ago
CVE-2026-66147 | SonicWall GMS up to 9.5.1 GMS Dispatcher Service command injection
→ No new info (linked only)
CVSS 3.19.4 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011
CWECWE-94
PublishedAug 11, 2026
Trending Score58
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-15409EXP
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 87
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 77
CRITICALCVE-2026-66145
CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Trending: 58
HIGHCVE-2026-66149
CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 49
HIGHCVE-2026-66150
CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 49

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 12, 2026