SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
ID: b393a5f5-7912-53fe-9996-2deb676cfa74
STIX ID: report--b393a5f5-7912-53fe-9996-2deb676cfa74
Feed Name: Cyber Press
SonicWall disclosed two high-severity vulnerabilities in the NetExtender Linux VPN client (affecting versions 10.3.5 and earlier): CVE-2026-66152 is a path traversal flaw that can result in arbitrary files being written to disk with root privileges (CVSS 8.8), and CVE-2026-66153 is an improper link resolution issue in the NEService auto-upgrade process (CVSS 7.0). The vendor released NetExtender Linux Client 10.3.6 to remediate both issues, stated there is no workaround, reported no evidence of in-the-wild exploitation, and recommends immediate upgrades for affected Linux deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
