Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-81939: SonicWall Network Security Manager can let attackers write files anywhere

CVE-2026-81939 · published today
Summary

The on‑premises SonicWall Network Security Manager allows users to upload zip archives. A specially crafted zip can cause the system to place files outside the intended folder, giving an attacker the ability to add or replace files on the server. Apply the latest SonicWall update and restrict file‑upload functions until the fix is deployed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sonicwall network security manager (nsm) 4.3.0 and earlier versions
Original advisory text
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destinatio...
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
Severity
9.1 Critical
Type
CWE-22Path Traversal
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-81939 · MITRE
Monitor software like this
Free during beta