SONICWALL has released a security bulletin highlighting three critical vulnerabilities in its on-premise management appliances, specifically the SonicWall Network Security Manager (NSM). The vulnerabilities allow attackers to bypass authorization controls and execute arbitrary commands, potentially leading to full control over affected systems.
Notable flaws include CVE-2026-78328, which involves missing authorization in the web management interface; CVE-2026-78327, permitting OS command injection; and CVE-2026-81939, representing a Zip Slip path traversal vulnerability. Affected versions include NSM version 4.3.0 and earlier on various hypervisors, while cloud-hosted SaaS versions are safe. SonicWall has issued a patch (version 4.3.1-R4) to address these issues, with no temporary workarounds available.
The vulnerabilities are considered serious operational risks as they allow privilege escalation and could enable malicious changes to network firewall policies.