VORANT. Threat Intelligence Sign in Get the full feed

SonicWall NSM On-Prem flaws enable RCE

routine vulnerability technologyinfrastructure

CERT-FR warns of multiple SonicWall Network Security Manager On-Prem vulnerabilities allowing remote code execution, privilege escalation, and security bypass.

CERT-FR has issued an advisory covering multiple vulnerabilities in SonicWall's Network Security Manager (NSM) On-Prem product, affecting deployments on VMware, Hyper-V, Azure, and KVM prior to version 4.3.1-R4. The flaws collectively allow an attacker to bypass security policy controls, execute arbitrary code remotely, and escalate privileges on affected systems. Three CVEs are referenced: CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, corresponding to SonicWall's own security bulletin SNWLID-2026-0015 published on 03 September 2026.

No evidence of active exploitation is mentioned in the advisory. Organizations running affected NSM On-Prem versions should consult SonicWall's PSIRT bulletin for patch details and upgrade to 4.3.1-R4 or later. Given SonicWall NSM's role in centralized management of network security policy across firewalls, a successful RCE or privilege escalation exploit could have significant downstream impact on managed network infrastructure, warranting prompt patching even absent confirmed in-the-wild activity.

Mentioned in this report

Vulnerabilities CVE-2026-78327CVE-2026-78328CVE-2026-81939

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1115

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free