# SonicWall patches flaws in Email Security, GMS

Published: 2026-08-12 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/13b1dc9a-2295-5f2f-8176-75a4694fd4dd/sonicwall-patches-flaws-in-email-security-gms

> CERT-FR advisory details multiple vulnerabilities in SonicWall Email Security and GMS allowing RCE, privilege escalation and data exposure.

CERT-FR issued an advisory covering multiple vulnerabilities affecting SonicWall Email Security (versions prior to 10.0.36) and SonicWall GMS (versions prior to 9.5.2). The flaws span several vulnerability classes including remote code execution, privilege escalation, cross-site scripting, data integrity and confidentiality breaches, and security policy bypass.

SonicWall published two corresponding security bulletins (SNWLID-2026-0011 and SNWLID-2026-0012) alongside eight CVE identifiers. No indication of active exploitation is provided in the advisory; organizations running affected versions should apply vendor patches promptly given the potential for remote code execution and privilege escalation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18634, CVE-2026-66145, CVE-2026-66146, CVE-2026-66147, CVE-2026-66148, CVE-2026-66149, CVE-2026-66150, CVE-2026-66154

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1006

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/13b1dc9a-2295-5f2f-8176-75a4694fd4dd/sonicwall-patches-flaws-in-email-security-gms.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
