Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5044 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-66149PATCHED
sonicwall · email security

CVE-2026-66149: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows

Description

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

Affected Products

VendorProductVersions
sonicwallemail security10.0.35.8405 and earlier versions

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sonicwallemail securitycert_advisory90%

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012(vendor-advisory)

Related News (4 articles)

Tier B
BSI Advisories12h ago
[NEU] [mittel] SonicWall Email Security: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administratorrechten
→ No new info (linked only)
Tier D
SecurityWeek13h ago
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
→ No new info (linked only)
Tier B
CERT-FR21h ago
Multiples vulnérabilités dans les produits SonicWall (12 août 2026)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-66149 | SonicWall Email Security Restricted CLI netmask os command injection
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012
CWECWE-94
PublishedAug 11, 2026
Trending Score49
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-15409EXP
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 87
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 77
CRITICALCVE-2026-66147
CVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier
Trending: 58
CRITICALCVE-2026-66145
CVE-2026-66145: An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Trending: 58
HIGHCVE-2026-66150
CVE-2026-66150: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Trending: 49

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 12, 2026