Skip to content
SonicWallCVE-2026-78327

SonicWall Network Security Manager (NSM): command injection

Critical9.1CVE-2026-78327 · Published Sep 4, 2026 · updated Sep 8, 2026

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

SonicWall advisory

Affected versions

PackageAffectedFixed in
Network Security Manager (NSM)
Product
<= 4.3.0 and earlier versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-78

More SonicWall advisories

All SonicWall
Advisory
SonicWall Network Security Manager (NSM): path traversal
Critical9.1Sep 4
SonicWall Network Security Manager (NSM): missing authorization
Critical9.1Sep 4
SonicWall SMA1000: server-side request forgery
Critical10.0Sep 1
SonicWall SMA1000: command injection
High7.8Sep 1
SonicWall NetExtender: path traversal
High8.8Aug 25
SonicWall NetExtender: link following
High7.0Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.