【Vulnerability Alert】SonicWall NSM On-Prem Contains Two Critical Cybersecurity Vulnerabilities
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090708093434 | Publication Time | 2026-09-07 08:51:34 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-07 08:51:34 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】SonicWall NSM On-Prem Contains Two Critical Cybersecurity Vulnerabilities |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000002 SonicWall issued advisories regarding two critical cybersecurity vulnerabilities affecting NSM On-Prem (CVE-2026-78327, CVSS: 9.1, and CVE-2026-81939, CVSS: 9.1). CVE-2026-81939 is a Zip Slip vulnerability that exists in the file upload and compressed file handling functions of NSM On-Prem. An attacker may exploit a specially crafted file to extract files outside the intended target directory. CVE-2026-78327 is an OS Command Injection vulnerability that allows an authenticated attacker with SuperAdmin privileges to execute arbitrary commands on the underlying host, thereby resulting in remote code execution. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
Network Security Manager (NSM) On-Prem version 4.3.0 and earlier |
|||
|
[Recommended Actions] Please update to the following version: Network Security Manager (NSM) On-Prem version 4.3.1-R4 or later |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





