SonicWall has issued a advisory regarding critical security vulnerabilities in NSM On-Prem (CVE-2026-78327, CVSS: 9.1 and CVE-2026-81939, CVSS: 9.1). CVE-2026-81939 is a Zip Slip vulnerability residing in the file upload and archive handling functionality of NSM On-Prem, allowing attackers to extract files outside the intended target directory using crafted files. CVE-2026-78327 is an
OS Command Injection vulnerability that allows authenticated attackers with SuperAdmin privileges to execute arbitrary commands on the underlying host, resulting in remote code execution.