Multiple Critical Vulnerabilities in SonicWall GMS Enable Remote Code Execution
What Happened — The Center for Internet Security disclosed six new CVEs (CVE‑2026‑66145, CVE‑2026‑66146, CVE‑2026‑66147, CVE‑2026‑66148, CVE‑2026‑66154, CVE‑2026‑18634) affecting SonicWall Global Management System (GMS) versions 9.5.1 and earlier. The most severe flaw permits unauthenticated remote code execution (RCE) in the context of the service account, potentially allowing an attacker to install software, modify data, or create privileged accounts.
Why It Matters for Compliance & Audit Readiness
- The RCE scenario directly tests the effectiveness of your change‑control and patch‑management controls required by SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
- Demonstrating continuous evidence that vulnerable management consoles are patched or mitigated satisfies audit expectations for “risk mitigation” and provides defensible proof for third‑party assessments.
Who Is Affected – Enterprises that deploy SonicWall firewalls, wireless, email security, or remote‑access solutions managed through GMS, across government, large‑business, and MSP environments.
Recommended Actions
- Verify GMS version; upgrade to the latest patched release or apply vendor‑provided mitigations.
- Map the patch‑management control to your SOC 2 audit framework; capture patch‑deployment logs as continuous evidence.
- Conduct a focused configuration review of service‑account privileges to ensure least‑privilege principles.
- Integrate vulnerability‑scan results into your continuous‑compliance dashboard for real‑time audit readiness.
Source: CIS Advisory 2026‑083
Technical Notes –
- CVE‑2026‑66145: Unauthenticated RCE via zip‑slip path traversal.
- CVE‑2026‑66146: Multiple XSS flaws.
- CVE‑2026‑66147: Unauthenticated command injection.
- CVE‑2026‑66148: Authenticated command injection with root escalation.
- CVE‑2026‑66154: Insufficient certificate validation enabling MITM.
- CVE‑2026‑18634: Insecure deserialization leading to unauthorized actions.