CVE-2026-78327
published 2026-09-04CVE-2026-78327: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM)…
PriorityP264critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
1.55%
73.6th percentile
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sonicwall | network_security_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SonicWall Network Security Manager Management Interface os command injection
vuldb·2026-09-04·CVSS 9.1
CVE-2026-78327 [CRITICAL] SonicWall Network Security Manager Management Interface os command injection
A vulnerability, which was classified as very critical, was found in SonicWall Network Security Manager. The impacted element is an unknown function of the component Management Interface. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2026-78327. The attack can be launched remotely. No exploit exists.
GHSA
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authe
ghsa_unreviewed·2026-09-04
CVE-2026-78327 [CRITICAL] CWE-78 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authe
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-04
Published