SonicWall NetExtender Linux client security bypass flaws
SonicWall NetExtender Linux Client before 10.3.6 has vulnerabilities that let an attacker bypass security policy enforcement.
ANSSI (CERT-FR) published an advisory relaying a SonicWall security bulletin (SNWLID-2026-0013) describing multiple vulnerabilities in the NetExtender Linux Client affecting versions prior to 10.3.6. The flaws allow an attacker to circumvent the client's security policy controls, potentially undermining VPN access restrictions or endpoint compliance checks enforced by the client.
No evidence of active exploitation is noted in the advisory. Two CVEs are referenced: CVE-2026-66152 and CVE-2026-66153. Organizations using SonicWall NetExtender Linux Client should consult the vendor bulletin and update to version 10.3.6 or later to remediate the security policy bypass issue.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1084
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free