During the 303030 days ending July 171717, 202620262026, 141414 vendors issued 616161 relevant security advisories, including six critical-rated issues.
However, the more urgent signal is reachability, 262626 advisories involve flaws attackers can exploit remotely without authentication.
Dell, F5, Fortinet, and SonicWall products feature prominently in this month’s high-priority patching list. These devices commonly sit at the network edge, manage remote access, inspect traffic, or run core data-center functions.
A compromise can give an attacker a foothold ahead of the security controls the appliance is supposed to enforce. SonicWall SMA1000 administrators should act first.
SonicWall advisory SNWLID-2026-0008 addresses CVE-2026-15409, an unauthenticated server-side request forgery flaw rated CVSS 10.010.010.0, and CVE-2026-15410, a code-injection vulnerability rated 7.27.27.2.
Chaining the flaws can enable full remote code execution on an exposed remote-access appliance.
Enterprise Network Devices Exposed
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on July 141414, confirming active exploitation.
Reporting indicates attackers may have stolen credentials, session databases, and TOTP multi-factor authentication seed configurations from compromised systems. Patching alone may not remove the attacker’s access.
Organizations should update SMA1000 systems to version 12.4.3-0345312.4.3\text{-}0345312.4.3-03453 or 12.5.0-0283512.5.0\text{-}0283512.5.0-02835, conduct a forensic review, invalidate active sessions, rotate user, administrator, LDAP, and service-account credentials, and reset MFA seeds.
Devices with compromise indicators should be reimaged or redeployed rather than cleaned in place.
Fortinet FortiSandbox also requires immediate attention. CVE-2026-39808 and CVE-2026-25089 are unauthenticated OS command-injection vulnerabilities in its web interface.
Both can allow remote code execution through crafted requests, and CISA added them to KEV on July 161616.
CVE-2026-39808 affects FortiSandbox versions 4.4.04.4.04.4.0 through 4.4.84.4.84.4.8, while CVE-2026-25089 affects additional on-premises, cloud, and PaaS deployments.
Upgrade to FortiSandbox 4.4.94.4.94.4.9 or later, or 5.0.65.0.65.0.6 or later.
Remove management interfaces from public exposure, investigate for unexpected commands and outbound connections, rebuild any affected appliance, and rotate every credential the system accessed.
Because FortiSandbox processes malware samples and analysis data, attackers with appliance access may also access stored samples and cached results.
Dell released two critical advisories affecting EMC Networking OS10 and SmartFabric Manager: DSA-2026-240 and DSA-2026-317. Both carry CVSS 9.89.89.8 scores and affect switching and fabric-management environments.
The OS10 update includes hundreds of upstream Linux fixes, including CVE-2026-31431, the KEV-listed Linux kernel privilege-escalation issue known as “Dirty Frag.”
The key lesson is to patch the appliance, rather than count every bundled CVE. Enterprises need an accurate asset inventory that maps deployed switches, management platforms, versions, and exposure paths to each vendor advisory, Pulse said.
F5 also issued an out-of-band BIG-IP advisory, F5-K000161837, on July 151515. The CVSS 9.29.29.2 vulnerability is unauthenticated and network-reachable on BIG-IP application delivery controller and load-balancer tiers.
Organizations operating internet-facing BIG-IP systems should prioritize remediation, restrict management exposure, and review logs for anomalous administrative or application traffic.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.