SonicWall disclosed multiple vulnerabilities in Network Security Manager (NSM) On-Prem affecting version 4.3.0 and earlier. The affected deployments include VMware, Hyper-V, Microsoft Azure, and KVM environments under advisory SNWLID-2026-0015.
The Canadian Centre for Cyber Security and Guyana National CIRT issued follow-on notices urging administrators to review SonicWall’s advisory and apply applicable updates as they become available. Public notices did not provide CVE identifiers, severity ratings, vulnerability details, exploitation status, or specific fixed-version information.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-884 regarding the SonicWall NSM On-Prem vulnerabilities and advised affected users and administrators to review SonicWall's advisory and apply necessary updates.
SonicWall published advisory SNWLID-2026-0015 covering multiple vulnerabilities in Network Security Manager (NSM) On-Prem version 4.3.0 and earlier, including VMware, Hyper-V, Azure, and KVM deployments. The advisory information provided did not identify CVEs, vulnerability types, severity, or exploitation status.
SonicWall identified CVE-2026-78327 (SuperAdmin command injection), CVE-2026-78328 (Admin-to-SuperAdmin privilege escalation), and CVE-2026-81939 (Zip Slip path traversal) in NSM On-Prem. It advised upgrades to a fixed release, stated NSM SaaS is unaffected, and reported no evidence of exploitation in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecirt.gy
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.