Improper Certificate Validation in SonicWall GMS - CVE-2026-66154
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to make unauthorized changes.
The vulnerability exists due to improper certificate validation in a privileged communication workflow when operating under a machine-in-the-middle position on the local network. A remote attacker can intercept and manipulate communication to make unauthorized changes.
Exploitation requires controlled network conditions.