Two severe SonicWall NetExtender vulnerabilities impact Linux users today. These security flaws allow remote attackers to write arbitrary files as root and manipulate system paths. Administrators must deploy the provided software update immediately to protect their systems.
- Product: SonicWall NetExtender
- Vulnerabilities: 2 flaws (CVE-2026-66152, CVE-2026-66153)
- Highest severity: Awaiting analysis
- Worst impact: A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows...
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-66152 | Awaiting analysis | CWE-29 | — | Not exploited |
| CVE-2026-66153 | Awaiting analysis | CWE-59 | — | Not exploited |
Why It Matters
These SonicWall NetExtender vulnerabilities pose a severe risk to enterprise network security. By gaining root file write access, an attacker can completely compromise the underlying Linux host system. From there, they can alter critical configuration files, steal sensitive user data, or deploy persistent malware. Remote workers frequently rely on the NetExtender Linux Client to maintain secure access to corporate resources. Therefore, compromising this client grants malicious actors a dangerous foothold directly into trusted internal networks. This level of access bypasses traditional perimeter defenses and accelerates lateral movement across the organization.
How the Attack Works
The first vulnerability, identified as CVE-2026-66152, is a critical path traversal weakness. This flaw exists within the OPSWAT tarball component of the software package. It allows an attacker to bypass standard file directory restrictions. By exploiting this weakness, an attacker can “write arbitrary file as root”.
The second vulnerability, CVE-2026-66153, centers on improper link resolution before file access. Specifically, the NEService auto-upgrade process insecurely handles temporary files during its normal execution cycle. Because of this insecure handling, the process “allows an attacker to manipulate file paths”. An attacker can use this local vulnerability to trick the system into modifying unintended targets.
Affected Versions
These issues directly affect the NetExtender Linux Client version 10.3.5 and all earlier versions. However, the NetExtender Windows-based client versions are completely unaffected by these specific security defects. The official vendor advisory states that “There is no evidence that these vulnerabilities are being exploited in the wild”. Furthermore, the vendor report does not disclose the total number of active user installations or affected deployments.
Patch or Mitigation Steps
System administrators should apply the patch immediately to secure their endpoints. The vendor explicitly states, “SonicWall strongly advises users of the NetExtender Linux client to upgrade to the mentioned fixed release version to address these vulnerabilities”. To mitigate these threats, users must download and install NetExtender Linux Client version 10.3.6 or higher. No alternative workarounds are provided.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!