Security Policy Bypass Vulnerabilities in SonicWall NetExtender
Multiple vulnerabilities, CVE-2026-66152 and CVE-2026-66153, in SonicWall NetExtender Linux Client versions prior to 10.3.6 allow attackers to bypass security policy enforcement.
CVE search metadata
CVE search record: CVE-2026-66152. KEV: no. Product: NetExtender Linux Client. Brief: Security Policy Bypass Vulnerabilities in SonicWall NetExtender. Brief link: https://feed.craftedsignal.io/briefs/2026-08-sonicwall-netextender/
CVE search record: CVE-2026-66153. KEV: no. Product: NetExtender Linux Client. Brief: Security Policy Bypass Vulnerabilities in SonicWall NetExtender. Brief link: https://feed.craftedsignal.io/briefs/2026-08-sonicwall-netextender/
The French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple security vulnerabilities impacting the SonicWall NetExtender Linux Client. Identified by the vendor as SNWLID-2026-0013, these flaws are tracked as CVE-2026-66152 and CVE-2026-66153. The vulnerabilities affect all versions of the NetExtender Linux Client prior to 10.3.6. These flaws allow an attacker to bypass established security policy controls, potentially granting unauthorized access to internal network segments or bypassing restrictions enforced by the VPN client. Organizations utilizing the NetExtender Linux client must upgrade to version 10.3.6 or later to mitigate the risk of policy circumvention.
Impact
Successful exploitation allows an attacker to bypass security policies enforced by the NetExtender client. This may result in unauthorized access to restricted network resources or the circumvention of traffic-filtering rules usually applied to remote VPN sessions. The scope of impact is limited to environments where the vulnerable NetExtender Linux Client is deployed.
Recommendation
- Upgrade the SonicWall NetExtender Linux Client to version 10.3.6 or later on all impacted endpoints to resolve CVE-2026-66152 and CVE-2026-66153.
- Audit logs for unexpected network connections or policy access denials originating from endpoints running vulnerable versions of the NetExtender client prior to patching.
Immediate actions
Inventory all Linux assets running SonicWall NetExtender and deploy version 10.3.6
Mitigations
Upgrade NetExtender Linux Client to 10.3.6
CVE-2026-66152, CVE-2026-66153