Bg ShapeBg Shape
THREAT INTELLIGENCE

Multiple Vulnerabilities in SonicWall GMS and Email Security

Affected Environment
SonicWall Global Management System virtual appliance and Windows, plus Email Security appliance and virtual deployments.

Threat Overview
Eight vulnerabilities include unauthenticated remote code execution, command injection, privilege escalation, and certificate weaknesses.

Exposure Timeline
Disclosed 12 August 2026; no active exploitation reported by SonicWall at time of publication.

Attack Surface
Exposed GMS management services and Email Security netmask and SNMP configuration parameters accepting unsanitized input.

Technical Root Cause
Zip Slip path traversal, insecure deserialization, insufficient certificate validation, and unsanitized command parameters.

Exploitation Pathway
Remote attacker exploits public facing management service to execute code, escalate privileges, or intercept traffic via MitM.

Operational Impact
Successful exploitation grants root level code execution, data exposure, and full administrative control over systems.

Strategic Impact
Compromised management infrastructure threatens centralized visibility across all SonicWall managed firewalls and gateways.

Required Mitigation
Upgrade GMS to 9.5.2 and Email Security to 10.0.36 or higher immediately after testing.

Incident Response Guidance
Restrict management interface exposure, review logs for command injection attempts, and monitor certificate failures.

References
SonicWall PSIRT

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image