logo

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

ID: 6188663b-dfef-5183-b1d9-02ce311564e2

STIX ID: report--6188663b-dfef-5183-b1d9-02ce311564e2

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

Author: Divya

...
...

**SonicWall released updates addressing two vulnerabilities in NetExtender Linux Client:** CVE-2026-66152 is a path traversal in an OPSWAT tarball that can allow arbitrary file writes as root (CVSS 8.8), and CVE-2026-66153 is an insecure temporary-file/symlink handling issue in the NEService auto-upgrade (CVSS 7.0); administrators should upgrade to NetExtender 10.3.6 as SonicWall provides no workaround and reports no current evidence of exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.