Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-81939
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
CVE-2026-78328
Privilege Escalation via Missing Authorization in SonicWall Network Security Manager On‑Prem Management Interface
CVE-2026-78327
OS Command Injection Allowing Remote Code Execution in SonicWall Network Security Manager On‑Prem Management Interface
CVE-2026-83549
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVE-2026-83548
Unauthenticated SSRF in SonicWall SMA1000 Work Place Interface
