Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical SonicWall NetExtender CVE-2024-XXXX allows root file write
August 26, 2026
Critical WordPress Plugin Vulnerability Exposes 400,000 Sites
August 26, 2026
Iran-Linked Hackers Exploit Legitimate Dev Tool to Conceal Didoor Backdoor
August 26, 2026
Home/CyberSecurity News/Critical SonicWall NetExtender CVE-2024-XXXX allows root file write
CyberSecurity News

Critical SonicWall NetExtender CVE-2024-XXXX allows root file write

Key Takeaways SonicWall has addressed two critical security flaws in its NetExtender Linux client. The most severe vulnerability, CVE-2026-66152, is a path traversal flaw allowing arbitrary root file...

David kimber
David kimber
August 26, 2026 3 Min Read
4 0

Key Takeaways

  • SonicWall has addressed two critical security flaws in its NetExtender Linux client.
  • The most severe vulnerability, CVE-2026-66152, is a path traversal flaw allowing arbitrary root file writes.
  • A second flaw, CVE-2026-66153, is an improper link resolution issue affecting the auto-upgrade process.
  • Both vulnerabilities impact NetExtender Linux Client versions 10.3.5 and earlier.
  • Organizations should immediately upgrade to NetExtender Linux Client version 10.3.6 or later.

SonicWall has issued an urgent security notice regarding two significant vulnerabilities discovered in its NetExtender Linux client. Among these is a critical path traversal vulnerability that could enable an attacker to write arbitrary files to a system with root privileges.

Table Of Content

  • Key Takeaways
  • SonicWall NetExtender Vulnerabilities
  • What You Should Do

The affected software includes NetExtender Linux Client versions 10.3.5 and all prior releases. A patched version, 10.3.6, has been made available to address these issues. The more severe of the two, identified as CVE-2026-66152, has been assigned a CVSS score of 8.8, indicating a high level of risk.

According to SonicWall, the primary flaw stems from how the Linux client processes OPSWAT tarball archives. This vulnerability permits a remote attacker to exploit path traversal sequences, directing files to be extracted outside their intended directories.

Given that the extraction process operates with root permissions, successful exploitation of this vulnerability could lead to arbitrary file writes with the highest system privileges. This poses a severe risk for privilege escalation on Linux systems, as an attacker could potentially manipulate critical system files or introduce malicious scripts.

For instance, an attacker might overwrite vital configuration files, inject malicious scripts into directories accessed by privileged processes, or modify system startup files. The ultimate impact of such an attack would vary depending on the specific target environment, existing file permissions, and whether user interaction could be leveraged to facilitate a malicious update or archive.

SonicWall NetExtender Vulnerabilities

The critical vulnerability, CVE-2026-66152, is classified under CWE-29, or Path Traversal. This category encompasses attacks that leverage special path sequences, such as “..,” to break out of a designated directory. In scenarios involving archive extraction, insecure handling of file paths can permit specially crafted entries within an archive to be written to unintended locations on the system.

In addition to the path traversal flaw, SonicWall also resolved CVE-2026-66153, an improper link resolution vulnerability found in the NetExtender Linux client. This flaw affects the NEService auto-upgrade mechanism, which handles temporary files insecurely.

A local attacker with access to the system could exploit this weakness by manipulating file paths through symbolic links, potentially influencing where files are accessed or written. CVE-2026-66153 carries a CVSS score of 7.0 and falls under CWE-59, known as Improper Link Resolution Before File Access, or a symlink-following issue.

Such vulnerabilities become particularly dangerous when privileged software performs file operations in temporary locations that are either controlled by an attacker or are easily predictable. SonicWall’s advisory indicates that the path traversal vulnerability (CVE-2026-66152) has a network attack vector and requires user interaction, while the improper link resolution flaw (CVE-2026-66153) is a local attack necessitating low privileges but high attack complexity. Both vulnerabilities, if exploited, could compromise confidentiality, integrity, and availability.

As of now, SonicWall has stated there is no evidence suggesting either vulnerability has been exploited in the wild. However, given NetExtender’s widespread use for providing remote access to corporate networks, prompt patching is crucial for organizations utilizing the Linux client. The vulnerabilities are detailed in SonicWall advisory SNWLID-2026-0013, published on August 25, 2026. No workarounds are currently available.

It is important to note that Windows-based NetExtender client versions are not affected by these specific vulnerabilities.

What You Should Do

  • Immediately upgrade all affected NetExtender Linux Client installations from version 10.3.5 or earlier to version 10.3.6 or later.
  • Identify any unmanaged Linux endpoints within your network and verify the installed NetExtender client versions.
  • Review privileged software update mechanisms for any unsafe archive extraction or temporary-file handling practices that could introduce similar vulnerabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical WordPress Plugin Vulnerability Exposes 400,000 Sites

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 127.0.6533.73 Patches 10 Critical Vulnerabilities
August 26, 2026
28,000 Git Repositories Exposed API Keys, Bank Details
August 26, 2026
New CoreRAT Malware Grants Full Control to Core Werewolf Hackers
August 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us