CVE-2026-66147Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-12: 2Mentions · 2026-08-13: 2Patch / Workaround · 2026-08-12: 2Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 208-1208-13
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-122
Patch2
2026-08-132
Disclosure1Patch1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    SonicWall GMS vulnerability CVE-2026-66147 (CVSS 9.4) enables unauthenticated remote code execution. Patch GMS to 9.5.2 without delay. #SonicWall #CVE #RCE #GMS #EmailSecurity #InfoSec http://securityonline.info/sonicwall-gms-rce-vulnerability/

    Post summary

    The post warns that CVE-2026-66147 in SonicWall GMS allows unauthenticated RCE (CVSS 9.4) and urges immediate patching to version 9.5.2.

    02021433
    13.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities in #SonicWall Global Management System (GMS), including critical flaws allowing unauthenticated remote code execution (CVE-2026-66145, CVE-2026-66147). Advisory at: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011 #Patch #Patch #Patch

    Post summary

    The advisory highlights critical unauthenticated remote code execution flaws in SonicWall GMS and provides a link and #Patch reference to the remediation.

    01000380
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 1) CVE-2026-66145 - An unauthenticated remote code execution vulnerability 3) CVE-2026-66147 - GMS Unauthenticated Command Injection in Dispatcher Service SonicWall GMS Security Affected By Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0011

    Post summary

    The text discloses two unauthenticated RCE and command injection vulnerabilities affecting SonicWall GMS, referencing the vendor PSIRT advisory.

    00000457
    7.0K followersView on X
  • TECHEPAGES@techepages
    Patch

    SonicWall has released patches for eight vulnerabilities, including two critical RCE flaws (CVE-2026-66147, CVE-2026-66145) in its discontinued Global Management System (GMS). The issues could allow unauthenticated remote code execution and data disclosure. Fixes are available in GMS v9.5.2 and Email Security v10.0.36.

    Post summary

    SonicWall released patches for two critical RCE vulnerabilities (CVE-2026-66147, CVE-2026-66145) affecting its GMS, with fixes available in GMS v9.5.2 and Email Security v10.0.36.

    0000038
    38 followersView on X

Explore more