What is CVE-2026-66150?
CVE-2026-66150 is a `Code Injection` vulnerability in the SonicWall Email Security appliance, allowing an authenticated attacker with restricted CLI access to inject arbitrary OS commands as root through SNMP. This could lead to full system compromise. Immediate patching with the vendor's security update is strongly advised.
Azərbaycanca: CVE-2026-66150, SonicWall Email Security cihazında autentifikasiya olunmuş hücumçunun məhdud CLI üzərindən SNMP vasitəsilə root səviyyəsində əmr yeridə bilməsinə imkan verən `Code Injection` zəifliyidir. Bu, cihazın tam ələ keçirilməsinə səbəb ola bilər. Dərhal vendor tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: SonicWall
FAQ2
What prerequisites must an attacker have to exploit CVE-2026-66150?
The attacker must have authenticated access to the restricted CLI on the SonicWall Email Security appliance.
What is the most severe potential outcome of successfully exploiting CVE-2026-66150?
It could lead to injection of commands at the root level via SNMP, resulting in a full system compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.