← Back to CVE List
Vulnerability Intelligence Report

CVE-2026-66149

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
SonicWall Email Security 10.0.35.8405 and earlier versions (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2026-07-24T08:34:11
Published2026-08-11T20:18:25
Patch Date2026-08-11
Last Updated2026-08-12T04:00:41

LINK COPIED TO CLIPBOARD