A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in.

Six advisories carried critical CVSS scores. The greatest danger sits in devices placed at the network edge.

Remote access gateways, firewalls, switches, load balancers, and security appliances are often reachable from outside, giving attackers a possible route into the systems they are meant to protect.

InfraTrust said in a report shared with Cyber Security News (CSN) that its analysts noted two SonicWall SMA1000 flaws were already exploited in real attacks, while several other weaknesses offered unauthenticated paths to disruption or remote code execution.

The report shows why patch teams should not rank every issue by CVSS alone.

A lower-scored bug exposed to the internet may demand faster action than a critical flaw requiring local administrator access, especially when exploit activity or public attack research already exists.

InfraTrust Report Flags 26 Unauthenticated Vulnerabilities

SonicWall advisory SNWLID-2026-0008 received the highest urgency. CVE-2026-15409 is an unauthenticated server-side request forgery flaw rated CVSS 10.0. It can be chained with CVE-2026-15410, a code-injection issue, to gain full remote code execution on an SMA1000 appliance.

CISA added both flaws to its Known Exploited Vulnerabilities catalog on July 14. Earlier SonicWall SMA1000 zero-day coverage explains how the weaknesses can be combined, while InfraTrust warns that simply installing the update may not remove damage already caused by an intruder.

Fortinet FortiSandbox also required attention. CVE-2026-39808 and CVE-2026-25089 are unauthenticated operating system command-injection flaws that can lead to appliance takeover.

Vendor advisories by severities (Source – InfraTrust)

The first affects versions 4.4.0 through 4.4.8, while the second reaches additional on-premises, cloud, and platform deployments.

Dell published critical updates for EMC Networking OS10 and SmartFabric Manager, both rated CVSS 9.8. F5 separately issued an unauthenticated, network-reachable BIG-IP advisory rated 9.2.

Previous F5 BIG-IP exploitation warnings underline the risk created when exposed traffic-management systems become attack targets.

Juniper disclosed network-based denial-of-service bugs in the Junos TCP proxy and SIP ALG on MX and SRX devices. Fortinet also addressed unauthenticated VNC access on FortiSandbox.

InfraTrust recommends sorting this queue by exposure, reachability, known exploitation, and business importance before using CVSS as a tiebreaker.

Exploitation Requires Recovery Beyond Routine Patching

Evidence from the SonicWall attacks indicates intruders stole valuable credentials, active session databases, and time-based one-time password seed configurations.

Additional SonicWall zero-day attack findings show why organizations must treat a previously exposed appliance as potentially compromised, even after deploying the vendor’s fixed software.

SMA1000 operators should first update to version 12.4.3-03453 or 12.5.0-02835. They should then conduct a forensic review, rebuild physical or virtual appliances when compromise is found, change user and administrator passwords, rotate connected service-account credentials, reseed MFA tokens, and invalidate active sessions.

FortiSandbox users should move to 4.4.9 or later, or 5.0.6 or later, with cloud and platform deployments also upgraded to 5.0.6 or later.

A FortiSandbox proof-of-concept exploit adds urgency because accessible management interfaces can turn a known weakness into a practical entry point.

The management interface should be removed from the public internet and restricted to an administrator network. Teams should hunt for unexpected processes, outbound connections, and modified jobs.

Any positive finding should trigger a rebuild rather than an attempt to clean the appliance while keeping it in service.

Credentials touched by a compromised sandbox should also be rotated, including local administrator, LDAP, and service accounts. Cached samples, analysis results, and stored data may have been readable after code execution.

These steps reduce the chance that stolen access survives after the vulnerable device is patched. InfraTrust’s broader lesson is simple: defenders need an accurate inventory and clear exposure data.

Teams should identify which appliances they operate, whether management services face the internet, and how critical each device is. That context reveals what to patch first during an intense disclosure cycle when advisory volume becomes overwhelming.