← Terug naar overzicht

A critical OS Command Injection vulnerability (CVE-2026-78327) has been identified in SonicWall Network Security Manager (NSM) On-Prem Management interface. The flaw allows an authenticated attacker with SuperAdmin privileges to inject arbitrary OS commands executed on the underlying host. Successful exploitation results in remote code execution on the affected system. The vulnerability is classified under CWE as Improper Neutralization of Special Elements used in an OS Command. It requires authentication with elevated SuperAdmin privileges to exploit. SonicWall has published an advisory via their PSIRT portal under SNWLID-2026-0015. The vulnerability is tracked by NVD at NIST and carries a high criticality rating. Organizations using SonicWall NSM On-Prem deployments should review the advisory and apply mitigations promptly.

Affected products

  • SonicWall Network Security Manager (NSM) On-Prem

Related CVE's

  • CVE-2026-78327

Categories

  • Enterprise Applications
  • Network Infrastructure
  • Zero-Day Vulnerabilities