{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/network-security-manager-on-prem--4.3.1-r4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Network Security Manager On-Prem (\u003c 4.3.1-R4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","privilege-escalation","patch-management"],"_cs_type":"advisory","_cs_vendors":["SonicWall"],"content_html":"\u003cp\u003eOn September 4, 2026, the French National Cybersecurity Agency (ANSSI) and SonicWall released advisories detailing multiple high-severity vulnerabilities affecting SonicWall Network Security Manager (NSM) On-Prem appliances. The affected products include virtual machine deployments across VMWare, Hyper-V, Azure, and KVM platforms running versions earlier than 4.3.1-R4. These vulnerabilities, specifically identified as CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, collectively expose organizations to risks of remote code execution, privilege escalation, and bypass of established security policies. Given the critical nature of these flaws and the potential for unauthenticated or elevated access within a central management platform, immediate patching is required. Organizations running affected versions should prioritize updates to release 4.3.1-R4 or later as outlined in vendor bulletin SNWLID-2026-0015.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthorized actors to execute arbitrary code with elevated privileges, potentially leading to full system compromise of the Network Security Manager appliance. As NSM is used for the centralized management of firewall environments, a breach of this platform could allow an attacker to gain broad control over network security policies, disable security controls, or facilitate lateral movement into protected internal network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all SonicWall Network Security Manager On-Prem appliances to version 4.3.1-R4 or later to remediate CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939. Monitor system logs for unexpected administrative account activity or unauthorized configuration changes following the application of the vendor patches.\u003c/p\u003e\n","date_modified":"2026-09-04T18:06:13Z","date_published":"2026-09-04T18:06:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-nsm-vulnerabilities/","summary":"SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.","title":"Multiple Vulnerabilities in SonicWall Network Security Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-nsm-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Network Security Manager On-Prem (\u003c 4.3.1-R4)","version":"https://jsonfeed.org/version/1.1"}