BoletimSecAugust 27, 2026🇵🇹Translated from Portuguese

SonicWall Patches Critical Path Traversal and Update Flaws in NetExtender for Linux

SonicWall has corrected two serious vulnerabilities in NetExtender for Linux that could permit arbitrary file writes with elevated privileges and interference with the update process.

The issues affect versions 10.3.5 and earlier. The more critical flaw, CVE-2026-66152, received a CVSS score of 8.8 and involves a path traversal vulnerability during processing of an OPSWAT file in tar format. A remote attacker can supply specially crafted paths to cause files to escape the expected directory during extraction. Because the operation runs with root privileges, files can be written to sensitive system locations. Depending on the environment, this may enable configuration changes, insertion of malicious scripts, or modification of files later loaded by privileged processes. Exploitation requires user interaction.

The second vulnerability, CVE-2026-66153, carries a CVSS score of 7.0 and affects the automatic update process of NEService. The problem is linked to improper handling of symbolic links and temporary files. To date, there is no evidence of either vulnerability being exploited in real-world attacks. SonicWall confirmed that NetExtender for Windows is not impacted.

No workaround is available. Administrators should update NetExtender Linux to version 10.3.6 or later without delay and verify any endpoints still running older builds.

Related articles

Security NEXTVulnerabilities & Exploits

Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA

Apache Tomcat has received updates addressing 11 vulnerabilities across versions 11.0.25, 10.1.59, and 9.0.121. The Apache Software Foundation rated four issues as Important, while CISA assigned Critical severity to four CVEs based on CVSS v3.1 scores reaching 9.8. The flaws include authentication bypasses, access control evasion due to path evaluation order, off-by-one errors, and HTTP/2 resource leaks leading to denial of service. One vulnerability was disclosed earlier in July, with the remaining ten detailed on August 25. Moderate and Low severity issues were also patched in the same releases. The discrepancies in severity ratings between the vendor and CISA highlight differing risk assessments for the same CVEs.

安全客Vulnerabilities & Exploits

Redis Patch Bypass Enables Multiple RCE Exploits as PoCs for TLS and Stream Vulnerabilities Go Public

Multiple remote code execution vulnerabilities have been disclosed in Redis over the past month, including a critical patch bypass for CVE-2026-25243 that reintroduces Double Free flaws via crafted stream operations. The latest issue, QVD-2026-58458 affecting the TLS pending list, now has full technical details and a working PoC available, following the earlier QVD-2026-55651 disclosure. All three flaws impact nearly every production version still in use, from Redis 6.2.22 and below through 7.4.9 and 8.6.4. Although authentication is required, widespread weak or empty password configurations and exposed instances make exploitation trivial for attackers. Successful compromise grants arbitrary code execution in the Redis process context, enabling standard post-exploitation steps such as credential harvesting and lateral movement across internal networks. Organizations are urged to inventory all instances, apply the latest patches immediately, restrict network access via ACLs, and monitor for anomalous use of commands like XGROUP, EVAL, and RESTORE.

Security NEXTVulnerabilities & Exploits

Cisco Pre-Announces Security Advisories and Patches for Multiple Products on September 2, 2026

Cisco Systems has disclosed plans to publish security advisories for several product lines on September 2, 2026. The advisories will cover vulnerabilities affecting IP telephony devices, network switches, and email security appliances. Targeted products include Cisco IOS XR Software, multiple series of Cisco Desk Phones, Nexus 9000 Series switches with Silicon One, and Cisco Secure Email. The company will also provide updates aimed at strengthening security in IOS XR. No CVE identifiers, vulnerability details, affected versions, or CVSS scores have been released at the pre-notification stage. Cisco strongly recommends applying the forthcoming fixes once they become available, while noting that the schedule and product scope may still change.

Security NEXTVulnerabilities & Exploits

CISA Adds Six Known Exploited Vulnerabilities Affecting NetScaler ADC, Linux Kernel and Microsoft SQL Server to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added six vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. One of the flaws, CVE-2026-8452, affects Citrix NetScaler ADC and NetScaler Gateway products and can trigger denial-of-service conditions under specific configurations. The remaining five issues, disclosed between 2015 and 2022, impact the Linux Kernel, Red Hat Automatic Bug Reporting Tool, and the libuser library. Exploitation of these older flaws can allow local attackers to escalate privileges or corrupt password files. Organizations are urged to apply available patches and verify configurations immediately.