CVE-2026-66153Patch

LOWCVSS 7.0 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-08-26: 6Patch / Workaround · 2026-08-26: 5Technical Details · 2026-08-26: 508-26
Signal classification2 categories
Patch
583.3%
Disclosure
116.7%
Referenced assets4 URLs
Full discourse6 posts
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 SonicWall NetExtender'da kritik güvenlik açığı! SonicWall'ın Linux istemcisi NetExtender'da iki güvenlik açığı tespit edildi. 👉 CVE-2026-66152 — CVSS 8.8 Path Traversal açığı, özel hazırlanmış bir OPSWAT tar arşivindeki dosyaların hedef dizin dışına çıkarılmasına izin veriyor. İşlemin root yetkileriyle gerçekleştirilmesi nedeniyle saldırgan, uygun koşullarda sistemde root yetkileriyle keyfi dosyalar yazabiliyor. 👉 CVE-2026-66153 — CVSS 7.0 NEService otomatik güncelleme mekanizmasındaki symlink (sembolik bağlantı) işleme hatası, yerel düşük yetkili bir saldırganın dosya işlemlerini manipüle etmesine neden olabiliyor. Etkilenen sürümler: NetExtender Linux 10.3.5 ve öncesi ✅ Çözüm: 10.3.6 veya üzeri SonicWall, şu an için bu açıkların aktif olarak istismar edildiğine dair bir kanıt bulunmadığını belirtiyor. Windows NetExtender istemcileri bu güvenlik açıklarından etkilenmiyor.

    Post summary

    The post announces two CVEs (CVE-2026-66152 and 2026-66153) affecting SonicWall NetExtender Linux 10.3.5 and below, provides technical details, notes no current exploitation, and recommends upgrading to version 10.3.6 or newer.

    00040746
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now. #SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153 https://securityonline.info/sonicwall-netextender-vulnerabilities/

    Post summary

    SonicWall alerts that two critical NetExtender Linux Client vulnerabilities exist and advises users to update to version 10.3.6.

    00022472
    13.0K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    1) CVE-2026-66152 - arbitrary file write via path traversal vulnerability 2) CVE-2026-66153 - Improper Link Resolution Before File Access ('Link Following') Vulnerability SonicWall NetExtender Linux Client Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013

    Post summary

    SonicWall discloses two new CVEs affecting the NetExtender Linux Client, detailing a path‑traversal based arbitrary file write and link‑following before file access vulnerabilities.

    00021502
    7.3K followersView on X
  • yousukezan@yousukezan
    Patch

    SonicWallのNetExtender Linux Clientに、root権限で任意ファイルを書き込まれる可能性がある脆弱性「CVE-2026-66152」と、シンボリックリンク処理の脆弱性「CVE-2026-66153」が見つかった。影響は10.3.5以前である。 CVE-2026-66152はOPSWATのtarball展開処理にあり、細工したパスを含むアーカイブによって本来の展開先外へファイルを書き込める。処理がroot権限で動くため、設定ファイルや起動関連ファイルなどを書き換えられる可能性がある。ネットワーク経由で悪用できるが、利用者の操作が必要とされる。 CVE-2026-66153はNEServiceの自動更新処理で一時ファイルを安全に扱わない問題で、ローカルの低権限ユーザーがシンボリックリンクを利用し、ファイルの参照先や書き込み先へ影響を与えられる可能性がある。 SonicWallによると、いずれも実際の攻撃での悪用は確認されていない。Windows版NetExtenderは影響を受けない。回避策はなく、Linux版を10.3.6以降へ更新する必要がある。 https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/

    Post summary

    SonicWall NetExtender Linux client contains two vulnerabilities enabling privileged file writes; no active attacks reported, but users must upgrade to version 10.3.6 or later to mitigate the issue.

    000301.3K
    16.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    ⚠️ PATCH NOW: A SonicWall NetExtender Linux flaw can let an attacker write arbitrary files as ROOT. There is: no workaround. CyberSignal Priority: 🔴 HIGH 📅 August 26, 2026 🏷️ VPN · Linux · Vulnerability 🆔 CVE-2026-66152 · CVE-2026-66153 SonicWall has disclosed two vulnerabilities affecting: NetExtender Linux Client 10.3.5 and earlier. The more serious flaw is: CVE-2026-66152 CVSS: 8.8 It involves path traversal when NetExtender processes an OPSWAT tar archive. An attacker may be able to escape the intended extraction directory and write files elsewhere. And the vulnerable operation runs as: root. So the chain could become: crafted archive ↓ path traversal ↓ file written outside intended folder ↓ privileged location modified ↓ potential escalation / persistence. Another flaw: CVE-2026-66153 CVSS: 7.0 This affects the auto-upgrade process and involves unsafe symbolic-link handling. A local low-privileged attacker may potentially influence privileged file operations. ✅ Fixed version Upgrade to: NetExtender Linux 10.3.6 or later. Important: Windows NetExtender is NOT affected by these two vulnerabilities. 🚨 Is it being exploited? Currently: ❌ no evidence of exploitation in the wild has been reported. So this is: ⚠️ PATCH NOW not: 🚨 ACTIVE EXPLOITATION. That distinction matters. 🛡️ What defenders should do ✅ find Linux systems running NetExtender ✅ verify versions ✅ upgrade to 10.3.6+ ✅ investigate unmanaged VPN clients ✅ review privileged update mechanisms ✅ monitor unexpected file creation by privileged NetExtender processes. VPN software sits close to: identity + remote access + privileged networking. That makes even non-exploited vulnerabilities worth prioritizing. Sources: SonicWall · Cyber Security News #CyberSecurity #SonicWall #Vulnerability

    Post summary

    The advisory informs about two high‑CVSS vulnerabilities in SonicWall NetExtender Linux, details the threat vectors, and directs users to patch to version 10.3.6 or newer, noting no current exploitation.

    0000088
    126 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Urgent patch alert: SonicWall NetExtender Linux client versions ≤10.3.5 contain two serious vulnerabilities—one (CVE-2026-66152) enabling remote path traversal and root file writes, another local symlink flaw (CVE-2026-66153). Update to version 10.3.6 ASAP to close off attack paths and safeguard remote access tools, archives & temp-file handling. #Vulnerability #NetExtender #LinuxSecurity #NetExtender #LinuxSecurity #Vulnerability #PathTraversal #RemoteAccess #SonicWall https://thedailytechfeed.com/critical-bugs-in-sonicwall-netextender-allow-root-level-file-writes-on-linux/

    Post summary

    The tweet serves as a patch alert for two CVEs in SonicWall NetExtender Linux client, advising an update to version 10.3.6 and detailing the path traversal and root file write vulnerabilities.

    0000045
    663 followersView on X

Explore more