Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090409095858 | Publication Time | 2026-09-04 09:10:06 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-04 09:10:06 |
| Impact Level | Medium | ||
| [Subject] 【Vulnerability Alert】SonicWall NetExtender Linux Contains a High-Risk Security Vulnerability (CVE-2026-66152). Please Confirm and Apply Patches as Soon as Possible |
|||
| [Content]
Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202609-00000004 Researchers discovered that SonicWall NetExtender Linux contains a Path Traversal vulnerability (CVE-2026-66152). An unauthenticated remote attacker may exploit the file decompression component to write arbitrary files with root privileges. Please confirm and apply patches as soon as possible. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
NetExtender Linux Client version 10.3.5 and earlier |
|||
|
[Recommended Actions] The official vendor has released a patch for the vulnerability. Please upgrade to NetExtender Linux Client version 10.3.6 or later. For detailed information, please refer to the official advisory. The URL is as follows: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013 |
|||
|
[Reference] 1. https://nvd.nist.gov/vuln/detail/CVE-2026-66152 |
|||