Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild

Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild

First seen 22 Jul 2026, 15:26 UTC BleepingcomputerSg.Finance.Yahoopulse.infra-trust.orgFeeds.4Sysopsfortiguard.fortinet.com 88% similarity 79.0

Article Content

Browse articles
ThreatCluster

The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and CVE-2026-15410 are being actively exploited, allowing attackers to execute remote code and exfiltrate sensitive data. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog on July 14, 2026, with a federal remediation deadline of July 17. Additionally, two Fortinet vulnerabilities (CVE-2026-39808 and CVE-2026-25089) were added to the KEV catalog on July 16, 2026, after being exploited in the wild. Organizations using these devices are urged to patch immediately and conduct forensic reviews to assess potential compromises. The report emphasizes prioritizing vulnerabilities based on exploitability and exposure rather than severity scores alone.

Key Points: • SonicWall's SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) are actively exploited. • Fortinet's CVEs (CVE-2026-39808, CVE-2026-25089) were added to CISA's KEV catalog after exploitation. • Organizations are advised to prioritize vulnerabilities based on real-world risk and exposure.

ThreatCluster AI

Timeline

2026-03-02
CVE-2026-21385 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-14
CVE-2026-39808 published
Fortinet disclosed a command injection vulnerability in FortiSandbox affecting unauthenticated users.
FortiGuard
2026-04-22
CVE-2026-31431 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
CVE-2026-25089 published
Fortinet announced a command injection vulnerability in FortiSandbox Cloud and PaaS WEB UI.
FortiGuard
2026-07-14
CVE-2026-15409 and CVE-2026-15410 added to CISA KEV
SonicWall vulnerabilities were recognized as actively exploited, with a federal patch deadline set.
Pulse.Infra-Trust
2026-07-16
CVE-2026-39808 and CVE-2026-25089 added to CISA KEV
Fortinet vulnerabilities were confirmed to be exploited in the wild, prompting urgent remediation actions.
BleepingComputer
2026-07-17
Federal remediation deadline for SonicWall vulnerabilities
Organizations were required to patch SonicWall devices to mitigate risks from active exploitation.
Pulse.Infra-Trust

Community

Browse all →