VORANT. Threat Intelligence Sign in Get the full feed

SonicWall patches flaws in Email Security, GMS

routine vulnerability technology

CERT-FR advisory details multiple vulnerabilities in SonicWall Email Security and GMS allowing RCE, privilege escalation and data exposure.

CERT-FR issued an advisory covering multiple vulnerabilities affecting SonicWall Email Security (versions prior to 10.0.36) and SonicWall GMS (versions prior to 9.5.2). The flaws span several vulnerability classes including remote code execution, privilege escalation, cross-site scripting, data integrity and confidentiality breaches, and security policy bypass.

SonicWall published two corresponding security bulletins (SNWLID-2026-0011 and SNWLID-2026-0012) alongside eight CVE identifiers. No indication of active exploitation is provided in the advisory; organizations running affected versions should apply vendor patches promptly given the potential for remote code execution and privilege escalation.

Mentioned in this report

Vulnerabilities CVE-2026-18634CVE-2026-66145CVE-2026-66146CVE-2026-66147CVE-2026-66148CVE-2026-66149CVE-2026-66150CVE-2026-66154

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1006

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free