started · updated
Palo Alto Networks and SonicWall disclose critical security vulnerabilities
Palo Alto Networks’ Expedition tool has been identified with several critical vulnerabilities, including OS command injection, SQL injection, and cross-site scripting (XSS). These flaws, with CVSS scores reaching 9.9, could allow unauthorized access, credential theft, and administrative takeover. The vulnerabilities, such as CVE-2024-9463 and CVE-2024-9464, enable attackers to run arbitrary commands as root, potentially exposing sensitive data like firewall credentials and API keys.
Separately, SonicWall has disclosed security vulnerabilities in its NetExtender Linux client. A critical path traversal flaw (CVE-2026-66152) with a CVSS score of 8.8 could allow a remote attacker to write arbitrary files with root privileges by exploiting how the client handles certain tarballs. Additionally, a separate improper link resolution vulnerability (CVE-2026-66153) affects the NEService auto-upgrade process, potentially allowing a local attacker to manipulate file paths via symbolic links.