# SonicWall NetExtender Linux client security bypass flaws

Published: 2026-08-26 · Severity: routine
Canonical: https://vorant.io/reports/31077aaf-ea3f-5ca6-851a-814f3b48ee9d/sonicwall-netextender-linux-client-security-bypass-flaws

> SonicWall NetExtender Linux Client before 10.3.6 has vulnerabilities that let an attacker bypass security policy enforcement.

ANSSI (CERT-FR) published an advisory relaying a SonicWall security bulletin (SNWLID-2026-0013) describing multiple vulnerabilities in the NetExtender Linux Client affecting versions prior to 10.3.6. The flaws allow an attacker to circumvent the client's security policy controls, potentially undermining VPN access restrictions or endpoint compliance checks enforced by the client.

No evidence of active exploitation is noted in the advisory. Two CVEs are referenced: CVE-2026-66152 and CVE-2026-66153. Organizations using SonicWall NetExtender Linux Client should consult the vendor bulletin and update to version 10.3.6 or later to remediate the security policy bypass issue.

## Mentioned in this report

- Vulnerabilities: CVE-2026-66152, CVE-2026-66153

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1084

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/31077aaf-ea3f-5ca6-851a-814f3b48ee9d/sonicwall-netextender-linux-client-security-bypass-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
