Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3752 articles · 207518 vulns · 36/41 feeds (7d)
← Back to list
7.0
CVE-2026-66153PATCHED
sonicwall · netextender

CVE-2026-66153: The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows

Description

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

Affected Products

VendorProductVersions
sonicwallnetextender10.3.5 and earlier versions

References

  • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013(vendor-advisory)

Related News (2 articles)

Tier B
CERT-FR7d ago
Multiples vulnérabilités dans SonicWall NetExtender (26 août 2026)
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-66153 | SonicWall NetExtender Auto Upgrade Process temp file
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0013
CWECWE-59
PublishedAug 25, 2026
Trending Score17
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-83548EXPKEV
CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
Trending: 119
HIGHCVE-2026-83549EXPKEV
CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
Trending: 116
HIGHCVE-2026-15410EXP
CVE-2026-15410: Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Trending: 107
HIGHCVE-2026-66152
CVE-2026-66152: A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to
Trending: 17
CRITICALCVE-2026-15409EXPKEV
CVE-2026-15409: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 27, 2026