CVE-2026-66152Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-29

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 6 mentions (2026-08-26); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-08-26: 6Mentions · 2026-09-02: 1Patch / Workaround · 2026-08-26: 5Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-26: 5Technical Details · 2026-09-02: 108-2609-02
Signal classification2 categories
Patch
571.4%
Disclosure
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-266
Disclosure2Patch4
2026-09-021
Patch1
Full discourse7 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 SonicWall NetExtender'da kritik güvenlik açığı! SonicWall'ın Linux istemcisi NetExtender'da iki güvenlik açığı tespit edildi. 👉 CVE-2026-66152 — CVSS 8.8 Path Traversal açığı, özel hazırlanmış bir OPSWAT tar arşivindeki dosyaların hedef dizin dışına çıkarılmasına izin veriyor. İşlemin root yetkileriyle gerçekleştirilmesi nedeniyle saldırgan, uygun koşullarda sistemde root yetkileriyle keyfi dosyalar yazabiliyor. 👉 CVE-2026-66153 — CVSS 7.0 NEService otomatik güncelleme mekanizmasındaki symlink (sembolik bağlantı) işleme hatası, yerel düşük yetkili bir saldırganın dosya işlemlerini manipüle etmesine neden olabiliyor. Etkilenen sürümler: NetExtender Linux 10.3.5 ve öncesi ✅ Çözüm: 10.3.6 veya üzeri SonicWall, şu an için bu açıkların aktif olarak istismar edildiğine dair bir kanıt bulunmadığını belirtiyor. Windows NetExtender istemcileri bu güvenlik açıklarından etkilenmiyor.

    Post summary

    Two critical CVEs affecting SonicWall NetExtender Linux clients were disclosed, detailing a path traversal and symlink processing flaw; no active exploitation has been reported, but a patch to version 10.3.6 or higher is available.

    00040746
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now. #SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153 https://securityonline.info/sonicwall-netextender-vulnerabilities/

    Post summary

    The post alerts to critical SonicWall NetExtender Linux client vulnerabilities (CVE‑2026‑66152/66153) and recommends updating to version 10.3.6 to remediate them.

    00022472
    13.0K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    1) CVE-2026-66152 - arbitrary file write via path traversal vulnerability 2) CVE-2026-66153 - Improper Link Resolution Before File Access ('Link Following') Vulnerability SonicWall NetExtender Linux Client Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013

    Post summary

    The text lists two SonicWall NetExtender Linux Client vulnerabilities with a PSIRT link, but provides no proof‑of‑concept, exploit details, active exploitation evidence, or patch information.

    00021502
    7.3K followersView on X
  • yousukezan@yousukezan
    Patch

    SonicWallのNetExtender Linux Clientに、root権限で任意ファイルを書き込まれる可能性がある脆弱性「CVE-2026-66152」と、シンボリックリンク処理の脆弱性「CVE-2026-66153」が見つかった。影響は10.3.5以前である。 CVE-2026-66152はOPSWATのtarball展開処理にあり、細工したパスを含むアーカイブによって本来の展開先外へファイルを書き込める。処理がroot権限で動くため、設定ファイルや起動関連ファイルなどを書き換えられる可能性がある。ネットワーク経由で悪用できるが、利用者の操作が必要とされる。 CVE-2026-66153はNEServiceの自動更新処理で一時ファイルを安全に扱わない問題で、ローカルの低権限ユーザーがシンボリックリンクを利用し、ファイルの参照先や書き込み先へ影響を与えられる可能性がある。 SonicWallによると、いずれも実際の攻撃での悪用は確認されていない。Windows版NetExtenderは影響を受けない。回避策はなく、Linux版を10.3.6以降へ更新する必要がある。 https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/

    Post summary

    SonicWall disclosed two Linux client CVEs that allow root‑privileged file write and symlink attacks; no real‑world exploitation was reported, and users are advised to update to version 10.3.6 or newer to mitigate.

    000301.3K
    16.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    SonicWall NetExtender の脆弱性 CVE-2026-66152/66153 が FIX:深刻なパス・トラバーサルの恐れ https://iototsecnews.jp/2026/08/26/sonicwall-netextender-vulnerabilities-allow-an-attacker-to-write-arbitrary-files-as-root/ SonicWall NetExtender Linux クライアントにおけるパス・トラバーサルおよびシンボリック・リンクに関する脆弱性を解説する記事です。リモート接続で広く活用されるソフトウェアにおいてアーカイブ展開や一時処理の安全確認が不十分な場合、システムの最重要権限の奪取や重要データの上書きといった深刻な問題が発生する恐れがあります。その影響として、root 権限での任意ファイル生成/システム制御権の失効/データの改ざんなどが懸念されます。対応策として求められるのは、バージョン 10.3.6 以降への速やかな更新/未管理端末の特定/更新処理の再検証などです。 #CVE202666152 #CVE202666153 #NetExtender #SonicWall #Vulnerability

    Post summary

    The post details the CVE‑2026‑66152/53 path‑traversal and symbolic link flaws in SonicWall NetExtender that can lead to arbitrary file creation with root privileges, and recommends an update to version 10.3.6 or later to mitigate the risk.

    00001111
    510 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    ⚠️ PATCH NOW: A SonicWall NetExtender Linux flaw can let an attacker write arbitrary files as ROOT. There is: no workaround. CyberSignal Priority: 🔴 HIGH 📅 August 26, 2026 🏷️ VPN · Linux · Vulnerability 🆔 CVE-2026-66152 · CVE-2026-66153 SonicWall has disclosed two vulnerabilities affecting: NetExtender Linux Client 10.3.5 and earlier. The more serious flaw is: CVE-2026-66152 CVSS: 8.8 It involves path traversal when NetExtender processes an OPSWAT tar archive. An attacker may be able to escape the intended extraction directory and write files elsewhere. And the vulnerable operation runs as: root. So the chain could become: crafted archive ↓ path traversal ↓ file written outside intended folder ↓ privileged location modified ↓ potential escalation / persistence. Another flaw: CVE-2026-66153 CVSS: 7.0 This affects the auto-upgrade process and involves unsafe symbolic-link handling. A local low-privileged attacker may potentially influence privileged file operations. ✅ Fixed version Upgrade to: NetExtender Linux 10.3.6 or later. Important: Windows NetExtender is NOT affected by these two vulnerabilities. 🚨 Is it being exploited? Currently: ❌ no evidence of exploitation in the wild has been reported. So this is: ⚠️ PATCH NOW not: 🚨 ACTIVE EXPLOITATION. That distinction matters. 🛡️ What defenders should do ✅ find Linux systems running NetExtender ✅ verify versions ✅ upgrade to 10.3.6+ ✅ investigate unmanaged VPN clients ✅ review privileged update mechanisms ✅ monitor unexpected file creation by privileged NetExtender processes. VPN software sits close to: identity + remote access + privileged networking. That makes even non-exploited vulnerabilities worth prioritizing. Sources: SonicWall · Cyber Security News #CyberSecurity #SonicWall #Vulnerability

    Post summary

    SonicWall announced two NetExtender Linux CVEs (CVE‑2026‑66152 and CVE‑2026‑66153) that allow path traversal and privilege escalation; no active exploitation has been reported, and users are urged to upgrade to version 10.3.6 or later to remediate the flaw.

    0000088
    126 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Urgent patch alert: SonicWall NetExtender Linux client versions ≤10.3.5 contain two serious vulnerabilities—one (CVE-2026-66152) enabling remote path traversal and root file writes, another local symlink flaw (CVE-2026-66153). Update to version 10.3.6 ASAP to close off attack paths and safeguard remote access tools, archives & temp-file handling. #Vulnerability #NetExtender #LinuxSecurity #NetExtender #LinuxSecurity #Vulnerability #PathTraversal #RemoteAccess #SonicWall https://thedailytechfeed.com/critical-bugs-in-sonicwall-netextender-allow-root-level-file-writes-on-linux/

    Post summary

    The alert warns of two serious path traversal and root file write vulnerabilities in SonicWall NetExtender Linux client and urges users to upgrade to version 10.3.6 immediately.

    0000045
    663 followersView on X

Explore more