# SonicWall NSM On-Prem flaws enable RCE

Published: 2026-09-04 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/e895846e-cf89-57cd-9aad-61d05cc4801d/sonicwall-nsm-on-prem-flaws-enable-rce

> CERT-FR warns of multiple SonicWall Network Security Manager On-Prem vulnerabilities allowing remote code execution, privilege escalation, and security bypass.

CERT-FR has issued an advisory covering multiple vulnerabilities in SonicWall's Network Security Manager (NSM) On-Prem product, affecting deployments on VMware, Hyper-V, Azure, and KVM prior to version 4.3.1-R4. The flaws collectively allow an attacker to bypass security policy controls, execute arbitrary code remotely, and escalate privileges on affected systems. Three CVEs are referenced: CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, corresponding to SonicWall's own security bulletin SNWLID-2026-0015 published on 03 September 2026.

No evidence of active exploitation is mentioned in the advisory. Organizations running affected NSM On-Prem versions should consult SonicWall's PSIRT bulletin for patch details and upgrade to 4.3.1-R4 or later. Given SonicWall NSM's role in centralized management of network security policy across firewalls, a successful RCE or privilege escalation exploit could have significant downstream impact on managed network infrastructure, warranting prompt patching even absent confirmed in-the-wild activity.

## Mentioned in this report

- Vulnerabilities: CVE-2026-78327, CVE-2026-78328, CVE-2026-81939

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1115

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e895846e-cf89-57cd-9aad-61d05cc4801d/sonicwall-nsm-on-prem-flaws-enable-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
