【Vulnerability Alert】SonicWall NSM On-Prem and SMA1000 Series Contain Multiple High-Risk Security Vulnerabilities (CVE-2026-78327, CVE-2026-83548, and CVE-2026-83549). Please Confirm and Apply Patches as Soon as Possible
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090908090808 | Publication Time | 2026-09-09 08:36:09 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-09 08:36:09 |
| Impact Level | Medium | ||
| [Subject] 【Vulnerability Alert】SonicWall NSM On-Prem and SMA1000 Series Contain Multiple High-Risk Security Vulnerabilities (CVE-2026-78327, CVE-2026-83548, and CVE-2026-83549). Please Confirm and Apply Patches as Soon as Possible |
|||
| [Content]
Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000008 Researchers discovered that SonicWall NSM On-Prem and the SMA1000 Series contain multiple high-risk security vulnerabilities (CVE-2026-78327, CVE-2026-83548, and CVE-2026-83549), including OS Command Injection and Server-Side Request Forgery vulnerabilities. Among them, CVE-2026-83548 and CVE-2026-83549 have been exploited by hackers. Please confirm and apply patches as soon as possible. 【CVE-2026-78327】A remote attacker who has obtained administrative privileges may inject arbitrary operating system commands through the management interface, thereby executing arbitrary code on the underlying host. 【CVE-2026-83548】An unauthenticated remote attacker may exploit an unintended alternate access path to access sensitive functions and perform unauthorized operations. 【CVE-2026-83549】Under specific conditions, an authenticated remote attacker may execute arbitrary operating system commands as an administrator through the Appliance Management Console (AMC), thereby executing arbitrary code. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
SonicWall NSM On-Prem (VMware, Hyper-V, Azure, and KVM) version 4.3.0 and earlier SonicWall SMA1000 Series (6210, 7210, and 8200v) platform-hotfix version 12.4.3-03453 and earlier SonicWall SMA1000 Series (6210, 7210, and 8200v) platform-hotfix version 12.5.0-02835 and earlier |
|||
|
[Recommended Actions] The official vendor has released remediation updates for the vulnerabilities. Please refer to the official instructions for updating. The URLs are as follows: 1. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015 |
|||
|
[Reference] 1. https://nvd.nist.gov/vuln/detail/CVE-2026-78327 |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





