logo

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

ID: b393a5f5-7912-53fe-9996-2deb676cfa74

STIX ID: report--b393a5f5-7912-53fe-9996-2deb676cfa74

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Tamilselvan

...
...

SonicWall disclosed two high-severity vulnerabilities in the NetExtender Linux VPN client (affecting versions 10.3.5 and earlier): CVE-2026-66152 is a path traversal flaw that can result in arbitrary files being written to disk with root privileges (CVSS 8.8), and CVE-2026-66153 is an improper link resolution issue in the NEService auto-upgrade process (CVSS 7.0). The vendor released NetExtender Linux Client 10.3.6 to remediate both issues, stated there is no workaround, reported no evidence of in-the-wild exploitation, and recommends immediate upgrades for affected Linux deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.