Pulse July 2026


By the numbers

This is the first edition of InfraTrust Pulse. This new monthly publication brings together security advisories, vulnerabilities, and other critical information about the hardware underpinning the world’s critical IT infrastructure. A handful of vendors build the network devices, servers, chips, firmware, baseboard management controllers (BMCs), and other crucial components that make everything else work. If the security of these components is compromised, so too are the devices, enterprises, and governments that rely on them.

In the thirty days ending July 17, 2026, the vendors we tracked issued 61 in-scope security advisories across 14 vendors. Six of those advisories are CVSS-critical. But CVSS does not tell the whole risk story. This month, what stood out to me were the vulnerabilities that can be exploited remotely without authentication. Twenty-six of the 61 advisories qualify, and one advisory, a SonicWall remote-access appliance, carries two CVEs that are already being exploited in the wild.

A note on how we count. We lead with advisories rather than raw CVE totals on purpose. A single Dell EMC Networking OS10 appliance OS update this month bundles hundreds of upstream Linux CVEs. Counting the vulnerabilities would tell you about Debian’s release cadence, not about your infrastructure risk. Your remediation strategy must map to the things you actually have to go patch.

What to patch first

SonicWall SMA1000 (SNWLID-2026-0008)

This advisory includes CVE-2026-15409 (unauthenticated SSRF, CVSS 10.0), which can be chained with CVE-2026-15410 (code injection, 7.2) to achieve full remote code execution. CISA added both to the Known Exploited Vulnerabilities catalog on July 14, with a federal deadline of July 17 under BOD 26-04. This is the only advisory this month with a vulnerability that is both newly exploited and specific to the appliance itself, and one of its CVEs scored a perfect CVSS 10.0 on an internet-facing remote-access appliance. If you run an SMA1000, you need to patch it, which only solves part of the problem, and then take immediate action.

Reporting on exploitation in the wild indicates that once the attackers were on the appliance, they exfiltrated high-value credentials, active session databases, and TOTP MFA seed configurations. This means that if any SMA1000 was compromised before you patched it, the attacker may already have working logins, live sessions, and the seeds needed to generate your users’ one-time codes. SonicWall says as much in its own guidance and recommends that every organization running these appliances perform a forensic review for indicators of compromise and treat any device as compromised rather than clean. If your SMA1000 was internet-facing before you patched, consider the following actions:

  • Patch to 12.4.3-03453 or 12.5.0-02835 first, then do everything below regardless of what you find.
  • Re-image the physical appliance or redeploy the virtual one if you find any indicator of compromise. Do not try to clean it in place.
  • Change every user and administrator password, and rotate the LDAP or other service-account credentials the appliance used, which were harvested for lateral movement.
  • Reset and re-seed the TOTP and MFA tokens, since the attacker may hold the current seeds.
  • Invalidate all active sessions.

Fortinet FortiSandbox (FG-IR-26-100 / FG-IR-26-141): CVE-2026-39808 and CVE-2026-25089

These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04.

Both are unauthenticated OS command-injection flaws (CWE-78) in the FortiSandbox web interface, accessible over the network without credentials, with no user interaction and low attack complexity. Each one is a straight path to remote code execution as the underlying system user, leading to full takeover of the appliance. CVE-2026-39808 is an injection flaw in a FortiSandbox API endpoint that can be exploited via crafted HTTP requests, and affects FortiSandbox 4.4.0–4.4.8 (5.0 and PaaS are not affected). Public exploit research attributes it to the job-detail/tracer-behavior endpoint via the jid parameter, though Fortinet’s advisory itself does not name the endpoint. 

CVE-2026-25089 is the broader of the two. It exploits the “start VNC” feature via crafted JSON and covers on-premises FortiSandbox (4.4.0–4.4.8 and 5.0.0–5.0.5) as well as FortiSandbox Cloud and PaaS (5.0.4–5.0.5). FortiSandbox is a malware-detonation appliance. It ingests attacker-supplied samples by design, stores analysis data, and typically contains service accounts and directory credentials. If your FortiSandbox management interface was network- or internet-reachable before you patched, assume exposure and work through the following:

  • Patch first by upgrading FortiSandbox to 4.4.9 or later, or 5.0.6 or later, and upgrade FortiSandbox Cloud and PaaS to 5.0.6 or later. (Older 4.2 builds are also listed as affected by CVE-2026-25089 and have no in-branch fix, so move them to 4.4.9 or later, or 5.0.6 or later.) Then do everything below regardless of what you find.
  • Remove it from the public internet. The management and web UI should never have been externally reachable; restrict them to an admin network.
  • Hunt for compromise by reviewing the appliance for indicators of command execution such as unexpected processes, outbound connections, and modified jobs. Treat any hit as a compromised device to be rebuilt, and do not attempt just to clean it and move on.
  • Rotate every credential the box touched, including local admin passwords and any LDAP or service accounts it used to reach monitored segments, since those are the pivot to lateral movement.
  • Assume the sample and analysis store, and any cached results, were readable by an attacker who obtained RCE.

Dell networking (DSA-2026-240 and DSA-2026-317, both CVSS 9.8)

Two of this month’s six criticals are Dell network infrastructure and a security update for EMC Networking OS10 (DSA-2026-240), and one for SmartFabric Manager (DSA-2026-317). Both are remotely exploitable, unauthenticated flaws in switching and fabric-management gear that sits within the data-center network. The OS10 advisory alone rolls up hundreds of upstream fixes, a reminder that a switch OS is a full Linux distribution with its full attack surface. Bundled in the DSA-2026-240 advisory is a fix for CVE-2026-31431, the now infamous “Dirty Frag” vulnerability, a local privilege escalation that was added to the CISA KEV on May 1, 2026.

F5 BIG-IP out-of-band notification (F5-K000161837, CVSS 9.2)

This is an out-of-band advisory F5 shipped on July 15. It is unauthenticated and network-reachable on the load-balancer and ADC tiers that sit in front of application traffic. Treat any internet-facing BIG-IP as a priority.

The other internet-facing criticals

The remotely exploitable, unauthenticated flaws that give attackers the easiest path this month also include a pair from Juniper and one more from Fortinet. Juniper shipped two unauthenticated, network-based denial-of-service bugs in the Junos TCP proxy and SIP ALG on MX and SRX Series (JSA110083 and JSA110086, both 8.7), and Fortinet left unauthenticated VNC access exposed on all interfaces of FortiSandbox (FG-IR-26-145, 8.6). No credentials are required, and all are network-reachable and typically exposed to the public internet.

The volume that hides serious bugs

Juniper (19 advisories) and Fortinet (7) top the count with a stack of remotely reachable, unauthenticated Junos and FortiOS issues. Palo Alto adds 12 PAN-OS advisories, but most are low severity, with the majority scoring below CVSS 5. Triage all of these and prioritize by internet exposure and business criticality, not by CVSS score.

Less Reachable But Still Important

NVIDIA BlueField and ConnectX, out-of-bounds write (Advisory 5699)

The AI fabric is critical, and one of those pieces is networking silicon rather than a GPU. Pay attention to security advisories related to the DPUs and SmartNICs in your AI and data-center servers, because a compromise can hand over control of your AI data center to a threat actor. The same silicon shows up a second way this month, since Lenovo re-ships the identical BlueField and ConnectX fixes in its own advisory (LEN-203310). If you run Lenovo servers with these adapters, track both.

Firmware and the slow lane

Several of this month’s advisories are firmware- and component-layer fixes, in which patching depends entirely on the hardware vendor’s integration timeline. Those include HP’s AMD Client UEFI firmware update (HPSBHF04133), HP’s InsydeH2O UEFI tools buffer overflow (HPSBHF04134), and Lenovo’s Multi-Vendor BIOS roundup (LEN-220440). The clearest example of the lag is HP’s Poly Video advisory (HPSBPY04106), which re-ships a Qualcomm KGSL GPU driver fix for CVE-2026-21385. This chipset bug was exploited and added to CISA’s KEV catalog back on March 3, four months before HP’s advisory shipped. This is the reality of hardware security. The fix exists upstream, and you still wait months for the OEM to build it into the product you own. Dell’s OS10 update inherits an older KEV-listed Linux kernel flaw the same way.

Qualcomm’s July bulletin (11 CVEs, CVSS up to 8.8) covers chipset and mobile fleets. Look for updates from your OEMs that include these chips, though that can take some time.

Analysis

The CVSS scores indicate six criticals this month, but the remote-and-unauthenticated vulnerabilities total 26, and those are not the same set you would get by sorting by score. A CVSS 7.5 that an attacker can reach across the internet with no credentials is a bigger problem for you than a 9.8 that needs local administrator rights. It underscores the importance of enriching vulnerability data beyond CVSS and of weighting reachability and exploit availability much higher than a standalone severity rating would.

The trends about rising network-edge attacks, noted in Verizon’s DBIR and Mandiant’s M-Trends reports, are borne out here. The large majority of this month’s in-scope advisories are network, security, and edge devices: the firewalls, VPN and remote-access gateways, routers, switches, and load balancers that are internet-facing by design and sit directly in the path of the traffic they are meant to protect. The remainder are server BMC and firmware, endpoint firmware, and chipset bulletins. The bug classes are consistent with that picture, with out-of-bounds reads and writes, buffer overreads, use-after-free, and a run of OS command injection on the management plane.

The exploited vulnerabilities demonstrate the point, and they do it from two opposite directions. SonicWall’s SMA1000 flaws were zero-days in the wild before CISA flagged them on July 14, which means a program that waits for the KEV entry to appear was already behind. The KEV-listed CVEs riding inside this month’s Dell and HP roll-ups make the opposite point about hardware’s slower failure mode. In these cases, the flaw is old and already weaponized, and the only thing anyone is waiting on is the vendor to ship the fix. Dell’s EMC Networking OS10 update (DSA-2026-240) carries CVE-2026-31431, the Linux kernel page-cache privilege-escalation flaw that the press first called “Copy Fail” and now circulates as the “Dirty Frag” exploit. Hence, a switch running OS10 inherits a root-level Linux exploit that attackers were using before the fix was even public. HP’s Poly Studio advisory (HPSBPY04106) is the same shape, re-shipping a Qualcomm KGSL GPU driver fix (CVE-2026-21385) for a memory-corruption flaw that reaches privileged memory on the Poly Studio X32, X52, X72, and G62 video devices. This chipset bug was exploited and added to CISA’s KEV catalog months earlier and is only now landing in the product you actually own. The cautionary tale is that the fix arrived well after the zero-day was published, leaving you exposed at the firmware and hardware layers that your other tools do not monitor

The takeaway this month is that a CVSS score is the wrong thing to sort your patch queue by, because the signal that actually predicts urgency is your own context. Position your teams to answer questions such as “Which of these appliances do we run?” and “How exposed are they?” 

Network infrastructure is where this matters most. The firewalls, VPN and remote-access gateways, routers, switches, and load balancers in this batch are internet-facing by design and sit directly in the path of the traffic they are meant to protect. A vulnerability in one of those devices can be reached from the outside without prior access. It sits in front of everything else you are trying to defend, and it hands an attacker a control point rather than a single host, which is exactly why the actively exploited flaw in this batch is a remote-access gateway rather than a desktop application. Sort by exposure and reachability, start with the internet-facing appliances you actually operate, and let the CVSS number be the tiebreaker rather than the ranking.

FAQ

A monthly rundown of the security advisories that matter for the hardware running everything. Network gear, servers, chips, firmware, and BMCs. A new edition every month.

Because you patch advisories, not raw CVE numbers; a single switch OS update can include hundreds of CVEs. Counting those measures Debian, not your risk.

The SonicWall SMA1000. It is a perfect 10.0, internet-facing, and already exploited. Then the two FortiSandbox command-injection flaws on CISA’s KEV list.

Because reachability is what attackers actually use, a 7.5 a stranger can hit from the internet beats a 9.8 that needs local admin. CVSS does not know what you expose.

Yes. It was a zero-day before CISA added it to KEV on July 14. Patching is step one. Assume compromise if it was exposed.

Because CISA added them to KEV on July 16, in the middle of the window. Old advisory, new urgency. Unauthenticated command injection on a security appliance earns the spot.