InfraTrust reported that 14 infrastructure vendors published 61 relevant advisories in the 30 days ending July 17, including 26 remotely reachable vulnerabilities that require no authentication and six advisories rated critical. The review said the highest risk remains concentrated in internet-exposed edge infrastructure such as remote access gateways, firewalls, switches, load balancers, and security appliances, and urged defenders to prioritize remediation based on exposure, reachability, known exploitation, and business importance rather than CVSS scores alone.
The most urgent issues were SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, which can be chained for full remote code execution and were added to CISA's Known Exploited Vulnerabilities catalog. The report also highlighted critical Fortinet FortiSandbox command-injection flaws, along with updates affecting Dell EMC Networking OS10, SmartFabric Manager, F5 BIG-IP, and Juniper denial-of-service bugs. For SonicWall and FortiSandbox appliances, the guidance warned that patching may be insufficient after exposure or exploitation and recommended forensic review, credential rotation, session invalidation, and rebuilding appliances where compromise is suspected.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
An infrastructure security review found that 14 infrastructure vendors issued 61 relevant advisories in the 30 days ending July 17. It identified 26 remotely reachable unauthenticated vulnerabilities and six advisories with critical CVSS scores.
CISA added Fortinet FortiSandbox vulnerabilities CVE-2026-39808 and CVE-2026-25089 to the Known Exploited Vulnerabilities catalog after exploitation was detected. Eclypsium highlighted the flaws as unauthenticated command injection issues in FortiSandbox advisories FG-IR-26-100 and FG-IR-26-141.
The InfraTrust report says SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were added by CISA to the Known Exploited Vulnerabilities catalog. The flaws were highlighted as especially urgent because they can be chained for full remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
eclypsium.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourceeclypsium.com
Open sourcepulse.infra-trust.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.