CVE-2026-66147: SonicWall Gms

Critical severity, CVSS 9.4. EPSS: 1.8% chance of exploitation in the next 30 days.

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

Affected products

Published 2026-08-11. Last modified 2026-08-28.