Posting Date: 2026/09/07
【Vulnerability Alert】2 Critical Security Vulnerabilities Found in SonicWall NSM On-Prem
- Subject: 【Vulnerability Alert】2 Critical Security Vulnerabilities Found in SonicWall NSM On-Prem
- Description:
- Forwarded security alert TWCERTCC-200-202609-00000002 from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC).
- SonicWall has issued a advisory regarding critical security vulnerabilities in NSM On-Prem (CVE-2026-78327, CVSS: 9.1 and CVE-2026-81939, CVSS: 9.1). CVE-2026-81939 is a Zip Slip vulnerability residing in the file upload and archive handling functionality of NSM On-Prem, allowing attackers to extract files outside the intended target directory using crafted files. CVE-2026-78327 is an OS Command Injection vulnerability that allows authenticated attackers with SuperAdmin privileges to execute arbitrary commands on the underlying host, resulting in remote code execution.
- Affected Platforms:
- Network Security Manager (NSM) On-Prem version 4.3.0 and prior versions
- Recommendations:
- Please update to the following version: Network Security Manager (NSM) On-Prem version 4.3.1-R4 and subsequent versions
- References:
Computer and Communication Center
Network System Division