SonicWall GMS Patched for Critical Unauth RCE Flaws
Critical unauthenticated RCE and data-read flaws patched in SonicWall GMS, which is end-of-life. If your GMS is internet-reachable, patch or isolate it now.
SonicWall patched multiple critical vulnerabilities in its Global Management System (GMS) — the centralized console used to manage SonicWall firewalls and VPN appliances — even though GMS has reached end-of-life status. SecurityWeek first reported the disclosures on August 12.
The security defects allow unauthenticated remote attackers to execute arbitrary code on the GMS host and read sensitive data from the management system. CVE assignments were not yet available in initial disclosures; consult SonicWall’s PSIRT advisory list for confirmed identifiers and affected version ranges as they publish.
What GMS Access Actually Means
GMS manages your firewalls and VPN gateways. An attacker who lands code execution on a GMS instance has a privileged position in your environment — not lateral movement to a file server, but configuration-level access to the appliances controlling network segmentation and remote access. That’s a high-impact outcome for a single unauthenticated entry point.
Why EOL Makes This Harder
Discontinued products accumulate monitoring debt. Patch cycles slow, alerting gets lighter, and the “it’s just internal” assumption tends to stick even when the product is managing perimeter gear. But GMS handles management traffic for devices that are, by definition, not internal-facing. The network path from a compromised internal host to GMS is often short.
The fact that SonicWall is shipping patches for an EOL product is the clearest possible signal that they consider this urgent. Match that urgency.
What to Do Right Now
- Apply SonicWall’s patches. Check SonicWall PSIRT for the specific advisory and affected version ranges. This is the only durable fix.
- Network-isolate GMS if you haven’t already. GMS should not be directly reachable from the internet. If it is, pull it off before anything else.
- Audit logs for anomalous access. Review GMS authentication and configuration-change logs going back at least two weeks.
- Accelerate your migration to NSM. SonicWall Network Security Manager is the supported successor. GMS got patched today; it may not next time.
SonicWall devices are under sustained attacker pressure right now. Ransomware operators have been actively exploiting SonicWall SMA1000 appliances as initial access vectors — CISA confirmed this August 10 and we covered it at CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000. Adding GMS to the picture means the full SonicWall management stack now has confirmed targets at both the appliance and the console layer.
Check current KEV entries and federal remediation deadlines on our KEV tracker.
Found this useful? Share it.


