Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Bluetooth Flaw Exposes 2.2M Cars to Remote Attacks
July 23, 2026
Critical SonicWall GMS, Analytics Flaws Let Attackers Execute Code
July 23, 2026
Chick-fil-A One Accounts Compromised in Data Breach
July 23, 2026
Home/Threats/Critical SonicWall GMS, Analytics Flaws Let Attackers Execute Code
Threats

Critical SonicWall GMS, Analytics Flaws Let Attackers Execute Code

Key Takeaways A recent security review highlighted 61 advisories from 14 infrastructure vendors in a single month, including 26 remotely exploitable vulnerabilities. SonicWall SMA1000 appliances are...

Jennifer sherman
Jennifer sherman
July 23, 2026 5 Min Read
3 0

Key Takeaways

  • A recent security review highlighted 61 advisories from 14 infrastructure vendors in a single month, including 26 remotely exploitable vulnerabilities.
  • SonicWall SMA1000 appliances are critically affected by two flaws (CVE-2026-15409, CVE-2026-15410) with a CVSS score of 10.0, which are actively being exploited and allow for remote code execution.
  • Fortinet FortiSandbox, Dell EMC Networking OS10, SmartFabric Manager, and F5 BIG-IP also received critical updates for vulnerabilities enabling appliance takeover or denial of service.
  • Simply patching may not be enough; forensic investigation and potential system rebuilds are crucial for devices like SonicWall SMA1000 due to evidence of data exfiltration.

Critical Flaws Emerge in Network Edge Devices, SonicWall Under Active Attack

The cybersecurity landscape has seen a flurry of activity, with a recent infrastructure security review revealing a significant number of vulnerabilities across critical network devices. Over a 30-day period ending July 17, 14 infrastructure vendors collectively issued 61 security advisories. Notably, 26 of these disclosed flaws are remotely accessible without authentication, posing an immediate threat to organizations.

Table Of Content

  • Key Takeaways
  • Critical Flaws Emerge in Network Edge Devices, SonicWall Under Active Attack
  • SonicWall SMA1000 Flaws Actively Exploited
  • InfraTrust Flags 26 Unauthenticated Vulnerabilities
  • Exploitation Necessitates Comprehensive Recovery Beyond Patching
  • What You Should Do

Six of these advisories were assigned critical CVSS scores, underscoring the severe risk to network infrastructure. A significant portion of these high-priority vulnerabilities reside in devices positioned at the network edge, such as remote access gateways, firewalls, switches, load balancers, and security appliances. Their inherent exposure to external networks makes them prime targets for attackers seeking initial access to protected systems.

SonicWall SMA1000 Flaws Actively Exploited

In a report shared with Cyber Security News (CSN), InfraTrust said in a report that its analysts identified two specific SonicWall SMA1000 vulnerabilities already being exploited in real-world attacks. These critical weaknesses offer unauthenticated pathways to disruption and remote code execution.

The report emphasizes that prioritizing vulnerabilities solely based on their CVSS score can be misleading. A lower-scored bug exposed to the internet, especially one with known exploit activity or publicly available attack research, may demand more urgent attention than a critical flaw that requires local administrator access.

InfraTrust Flags 26 Unauthenticated Vulnerabilities

The SonicWall advisory SNWLID-2026-0008 highlights a particularly urgent threat. CVE-2026-15409, an unauthenticated server-side request forgery (SSRF) vulnerability, received a perfect CVSS score of 10.0. This flaw can be chained with CVE-2026-15410, a code-injection issue, to achieve full remote code execution on an SMA1000 appliance.

Both CVEs were added to CISA’s Known Exploited Vulnerabilities catalog on July 14, confirming active exploitation. Previous coverage of SonicWall SMA1000 zero-days detailed how these vulnerabilities could be combined. InfraTrust cautions that merely applying the vendor’s update might not be sufficient to mitigate damage if an intruder has already compromised the system.

Beyond SonicWall, Fortinet FortiSandbox also requires immediate attention. CVE-2026-39808 and CVE-2026-25089 are unauthenticated operating system command-injection flaws that could lead to complete appliance takeover. The first affects versions 4.4.0 through 4.4.8, while the second extends to additional on-premises, cloud, and platform deployments.

Vendor advisories by severities (Source – InfraTrust)
Vendor advisories by severities (Source – InfraTrust)

Dell released critical updates for its EMC Networking OS10 and SmartFabric Manager, both scoring a CVSS of 9.8. Separately, F5 issued an advisory for an unauthenticated, network-reachable vulnerability in BIG-IP, rated 9.2. Past exploitation warnings for F5 BIG-IP underscore the inherent risk when exposed traffic-management systems become targets.

Juniper addressed network-based denial-of-service vulnerabilities in the Junos TCP proxy and SIP ALG on its MX and SRX devices. Fortinet also patched an issue involving unauthenticated VNC access on FortiSandbox. InfraTrust advises organizations to prioritize patching queues based on exposure, reachability, known exploitation, and business criticality, using CVSS scores as a tie-breaker rather than the sole ranking factor.

Exploitation Necessitates Comprehensive Recovery Beyond Patching

Evidence from the SonicWall attacks indicates that intruders successfully exfiltrated critical data, including valuable credentials, active session databases, and time-based one-time password (TOTP) seed configurations. These findings highlight why organizations must consider any previously exposed appliance as potentially compromised, even after applying vendor-provided fixes.

For SMA1000 operators, the immediate step is to update to version 12.4.3-03453 or 12.5.0-02835. Following the update, a thorough forensic review is essential. If a compromise is detected, physical or virtual appliances should be rebuilt, user and administrator passwords changed, connected service-account credentials rotated, MFA tokens reseeded, and all active sessions invalidated.

FortiSandbox users should upgrade to version 4.4.9 or later, or 5.0.6 or later, with cloud and platform deployments also moving to 5.0.6 or later. The existence of a proof-of-concept exploit for FortiSandbox underscores the urgency, as accessible management interfaces can quickly turn a theoretical weakness into a practical attack vector.

Management interfaces should be isolated from the public internet and restricted to secure administrator networks. Teams must actively hunt for unexpected processes, outbound connections, and modified scheduled jobs. Any positive finding should trigger a complete system rebuild rather than an attempt to clean the compromised appliance while it remains in service.

Credentials associated with a compromised sandbox, including local administrator, LDAP, and service accounts, must also be rotated. Cached samples, analysis results, and stored data may have been accessible to attackers after code execution. These comprehensive steps are vital to prevent stolen access from persisting after the vulnerable device is patched. InfraTrust’s overarching message is clear: defenders require an accurate asset inventory and precise exposure data to effectively prioritize patching during intense disclosure cycles.

What You Should Do

  • Patch Immediately: Apply all available updates for SonicWall SMA1000 (versions 12.4.3-03453 or 12.5.0-02835), Fortinet FortiSandbox (versions 4.4.9+, 5.0.6+), Dell EMC Networking OS10, SmartFabric Manager, F5 BIG-IP, and Juniper Junos devices.
  • Forensic Review & Rebuild: For SonicWall SMA1000 devices, conduct a thorough forensic investigation. If compromise is suspected or confirmed, rebuild the appliance from scratch.
  • Credential Rotation: Change all user and administrator passwords, rotate connected service-account credentials, and reseed MFA tokens for any system potentially affected by a SonicWall compromise.
  • Invalidate Sessions: Invalidate all active user sessions on potentially compromised SonicWall SMA1000 appliances.
  • Isolate Management Interfaces: Remove FortiSandbox and other critical management interfaces from direct exposure to the public internet, restricting access to internal administrator networks only.
  • Threat Hunt: Monitor for unexpected processes, outbound connections, and modified scheduled jobs on FortiSandbox and other critical network devices.
  • Inventory & Prioritize: Maintain an accurate inventory of all network-edge appliances, assess their internet exposure, and determine their business criticality to inform patching priorities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Chick-fil-A One Accounts Compromised in Data Breach

Next Post

Critical Bluetooth Flaw Exposes 2.2M Cars to Remote Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
July 23, 2026
Critical Adobe Acrobat Flaw Steals WhatsApp Chats From 329M Users
July 22, 2026
Critical RefluxFS Linux Kernel Bug Lets Attackers Gain Root Access
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us