CVE-2026-66147
An attacker can exploit multiple vulnerabilities in SonicWall GMS to elevate privileges, execute arbitrary code including code with root rights, bypass security measures, manipulate data, disclose confidential information, and conduct cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities enable privilege escalation, arbitrary code execution including root-level, security bypass, data manipulation, information disclosure, and cross-site scripting.
- Who is affected
- Deployments of SonicWall GMS across all affected versions.
- Urgency
- High severity with diverse attack vectors including root code execution; immediate remediation required despite no current exploitation.
- Action
- Apply patches for all six CVEs (CVE-2026-18634, CVE-2026-66145 through CVE-2026-66148, CVE-2026-66154) as soon as available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-66147
Get an email if CVE-2026-66147 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk2.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] SonicWall GMS: Multiple Vulnerabilitiescert-bund · 2026-08-12
- unknownMultiple vulnerabilities in SonicWall products (August 12, 2026)cert-fr-avis · 2026-08-12
- criticalCVE-2026-66147: An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Servic…nvd · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-66147)