SonicWall disclosed two vulnerabilities in NetExtender Linux Client versions 10.3.5 and earlier that can enable privileged file-path manipulation. Critical CVE-2026-66152 (CVSS 8.8) is a path-traversal issue in OPSWAT tarball handling that could let a remote, unauthenticated attacker—following user interaction—write arbitrary files as root outside the intended extraction directory. CVE-2026-66153 (CVSS 7.0) affects the NEService auto-upgrade process and lets a local low-privileged attacker abuse symbolic links to manipulate temporary-file paths.
SonicWall fixed both flaws in NetExtender Linux Client 10.3.6 and later under advisory SNWLID-2026-0013; no workaround is available. The company reported no evidence of active exploitation, and Windows-based NetExtender clients are unaffected. Organizations should promptly upgrade Linux clients, identify unmanaged Linux endpoints running affected releases, and review privileged archive-extraction and update processes for unsafe path and temporary-file handling.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
SonicWall published advisory SNWLID-2026-0013 disclosing CVE-2026-66152, a CVSS 8.8 path-traversal flaw enabling potential root-level arbitrary file writes, and CVE-2026-66153, a CVSS 7.0 improper link-resolution flaw in NEService auto-upgrade handling. Both affect NetExtender Linux Client 10.3.5 and earlier; SonicWall released fixes in version 10.3.6 and later, reported no evidence of in-the-wild exploitation, and stated that no workaround is available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.