Skip to content
Threat Feed
medium advisory

Security Policy Bypass Vulnerabilities in SonicWall NetExtender

Multiple vulnerabilities, CVE-2026-66152 and CVE-2026-66153, in SonicWall NetExtender Linux Client versions prior to 10.3.6 allow attackers to bypass security policy enforcement.

CVE search metadata

CVE search record: CVE-2026-66152. KEV: no. Product: NetExtender Linux Client. Brief: Security Policy Bypass Vulnerabilities in SonicWall NetExtender. Brief link: https://feed.craftedsignal.io/briefs/2026-08-sonicwall-netextender/

CVE search record: CVE-2026-66153. KEV: no. Product: NetExtender Linux Client. Brief: Security Policy Bypass Vulnerabilities in SonicWall NetExtender. Brief link: https://feed.craftedsignal.io/briefs/2026-08-sonicwall-netextender/

The French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple security vulnerabilities impacting the SonicWall NetExtender Linux Client. Identified by the vendor as SNWLID-2026-0013, these flaws are tracked as CVE-2026-66152 and CVE-2026-66153. The vulnerabilities affect all versions of the NetExtender Linux Client prior to 10.3.6. These flaws allow an attacker to bypass established security policy controls, potentially granting unauthorized access to internal network segments or bypassing restrictions enforced by the VPN client. Organizations utilizing the NetExtender Linux client must upgrade to version 10.3.6 or later to mitigate the risk of policy circumvention.

Impact

Successful exploitation allows an attacker to bypass security policies enforced by the NetExtender client. This may result in unauthorized access to restricted network resources or the circumvention of traffic-filtering rules usually applied to remote VPN sessions. The scope of impact is limited to environments where the vulnerable NetExtender Linux Client is deployed.

Recommendation

  • Upgrade the SonicWall NetExtender Linux Client to version 10.3.6 or later on all impacted endpoints to resolve CVE-2026-66152 and CVE-2026-66153.
  • Audit logs for unexpected network connections or policy access denials originating from endpoints running vulnerable versions of the NetExtender client prior to patching.

Immediate actions

Inventory all Linux assets running SonicWall NetExtender and deploy version 10.3.6

IT Operations 72h

Mitigations

Upgrade NetExtender Linux Client to 10.3.6

immediate IT Operations

CVE-2026-66152, CVE-2026-66153