ThreatCluster

SonicWall NetExtender Vulnerabilities Enable Root File Writes

First seen 26 Aug 2026, 17:36 UTC CybersecuritynewsGbhackers 71

Article Content

Browse articles
ThreatCluster

SonicWall has disclosed two critical vulnerabilities in its NetExtender Linux Client, allowing attackers to write arbitrary files with root privileges. The vulnerabilities affect versions 10.3.5 and earlier, with the most severe issue tracked as CVE-2026-66152, which has a CVSS score of 8.8/10. SonicWall released a patch in version 10.3.6 to address these issues. The vulnerabilities could potentially lead to significant unauthorized access and control over affected systems. Users are urged to upgrade to the latest version to mitigate risks. The vulnerabilities were published on August 25, 2026, and are now publicly known. Organizations using the affected versions should take immediate action to secure their systems.

Key Points: • Two critical vulnerabilities in SonicWall NetExtender allow root file writes. • CVE-2026-66152 has a CVSS score of 8.8/10 and affects versions 10.3.5 and earlier. • Users must upgrade to version 10.3.6 or later to mitigate these vulnerabilities.

Timeline

2026-08-25
CVE-2026-66152 published
SonicWall disclosed a critical path traversal vulnerability in NetExtender Linux Client.
Cybersecuritynews
2026-08-26
SonicWall releases security updates
SonicWall released version 10.3.6 to address the vulnerabilities affecting earlier versions.
Gbhackers