SonicWall on Tuesday announced patches for eight vulnerabilities across two products, including critical-severity remote code execution (RCE) bugs.

The cybersecurity firm rolled out fixes for six security defects in Global Management System (GMS), its centralized management, monitoring, and reporting platform that was retired in October 2025.

Per SonicWall’s advisory, two of the flaws, namely CVE-2026-66147 (CVSS score of 9.4) and CVE-2026-66145 (CVSS score of 9.1), deserve special attention, as both could allow remote, unauthenticated attackers to execute arbitrary code.

The former is described as a command injection issue in the GMS Dispatcher Service that can be exploited via crafted requests. The latter is an RCE bug leading to sensitive data disclosure and arbitrary file write via zipslip.

Impacting the 9.5.1 and earlier versions of GMS (Virtual Appliance and Windows), the vulnerabilities were resolved in version 9.5.2 of the software.

The update also addresses high-severity insufficient certificate validation and insecure handling of serialized objects bugs that could lead to unauthorized changes and actions.

On Tuesday, SonicWall also rolled out fixes for two high-severity code injection flaws (CVE-2026-66149 and CVE-2026-66150) in Email Security that could lead to OS command execution with root privileges.

Affecting ES Appliance 5000, 5050, 7000, 7050, 9000, VMware and Hyper-V, the two issues were resolved in Email Security version 10.0.36.

SonicWall says it has no evidence that any of these vulnerabilities have been exploited in the wild but urges users to apply the patches as soon as possible. Additional information can be found on SonicWall’s security advisories page.

Related: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Related: Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Related: Zoom Patches Zero-Click Code Execution Vulnerability