securityonline.info 8/26/2026, 2:01:26 AM · external

SonicWall NetExtender VPN flaws let attackers gain root on Linux

SonicWall NetExtender VPN flaws let attackers gain root on Linux
CyberSIXT Evidence Panel

TODAY , critical vulnerabilities have been detected in SonicWall's NetExtender VPN client, affecting Linux users. Specifically, two flaws, CVE-2026-66152 and CVE-2026-66153, allow remote attackers to write arbitrary files with root permissions, posing significant risks to network security. These vulnerabilities can lead to complete system compromise, making it imperative for administrators to apply the recommended software update (version 10.3.6 or higher) immediately to secure their systems.

Although no confirmed exploitation has been reported, the vulnerabilities exploit path traversal and improper link resolution, making them particularly dangerous. Windows-based clients are unaffected.

View Primary Source Via securityonline.info

Article by CyberSIXT