Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and CVE-2026-15410 are being actively exploited, allowing attackers to execute remote code and exfiltrate sensitive data. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog on July 14, 2026, with a federal remediation deadline of July 17. Additionally, two Fortinet vulnerabilities (CVE-2026-39808 and CVE-2026-25089) were added to the KEV catalog on July 16, 2026, after being exploited in the wild. Organizations using these devices are urged to patch immediately and conduct forensic reviews to assess potential compromises. The report emphasizes prioritizing vulnerabilities based on exploitability and exposure rather than severity scores alone.
Key Points: • SonicWall's SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) are actively exploited. • Fortinet's CVEs (CVE-2026-39808, CVE-2026-25089) were added to CISA's KEV catalog after exploitation. • Organizations are advised to prioritize vulnerabilities based on real-world risk and exposure.