GBHackers

26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers


A structural risk in enterprise infrastructure: unauthenticated, remotely exploitable vulnerabilities embedded in the very devices designed to secure networks.

In the 30 days ending July 17, 2026, 61 advisories across 14 vendors were disclosed, including six critical issues.

However, the more consequential signal lies elsewhere 26 of those advisories require no authentication. They are reachable over the network, dramatically lowering the barrier to exploitation.

Unlike raw CVE counts, advisory-level analysis provides a clearer picture of operational risk. A single advisory such as Dell’s OS10 update (DSA-2026-240) can bundle hundreds of upstream vulnerabilities, masking prioritization.

What matters is not volume, but exposure and exploitability across deployed infrastructure.

The most urgent case this cycle is SonicWall’s SMA1000 advisory (SNWLID-2026-0008), which includes CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410.

The first enables unauthenticated SSRF, which can be chained with a code injection vulnerability to achieve full remote code execution.

Both vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 14, confirming active exploitation.

Post-compromise activity observed in the wild includes exfiltration of credentials, session databases, and TOTP seeds, effectively allowing attackers to persist even after patching.

Fortinet’s FortiSandbox Vulnerabilities, tracked under FG-IR-26-100 and FG-IR-26-141, further demonstrate the risk of exposed management interfaces.

Vendor Advisories by severity (Source : InfraTrust).

CVE-2026-39808 and CVE-2026-25089 are unauthenticated OS command injection vulnerabilities reachable via crafted HTTP requests. Both were added to CISA’s KEV catalog on July 16.

The inaugural edition of InfraTrust Pulse highlights SonicWall explicitly warns that impacted appliances should be treated as compromised, reinforcing that patching alone is insufficient.

These vulnerabilities affect multiple deployment models, including on-premises and cloud, and enable full system compromise without user interaction.

26 Unauthenticated Vulnerability

Given FortiSandbox’s role in malware analysis pipelines, compromise can expose sensitive samples, credentials, and internal network visibility.

Network infrastructure vendors also contribute to this exposure surface. Dell’s SmartFabric Manager advisory (DSA-2026-317) and OS10 update include unauthenticated, remotely exploitable vulnerabilities affecting switching and fabric management layers.

The OS10 advisory also inherits CVE-2026-31431, the Linux kernel privilege escalation vulnerability known as “Dirty Frag,” already listed in KEV.

Similarly, F5’s out-of-band advisory (F5-K000161837) describes a high-severity unauthenticated issue in BIG-IP appliances, which often sit directly on the internet-facing edge.

Juniper’s advisories (JSA110083 and JSA110086) add denial-of-service vectors in MX and SRX platforms, while Fortinet’s additional advisory (FG-IR-26-145) exposes unauthenticated VNC access across interfaces.

These issues reinforce a consistent pattern: edge and management planes remain the most exposed and least hardened surfaces.

Beyond network appliances, firmware and silicon-layer vulnerabilities continue to lag in remediation cycles. NVIDIA’s BlueField advisory (5699) and Lenovo’s corresponding bulletin (LEN-203310) highlight risks in SmartNICs and DPUs powering AI infrastructure.

HP advisories such as HPSBHF04133 and HPSBPY04106 demonstrate delayed OEM integration of upstream fixes, including KEV-listed vulnerabilities like CVE-2026-21385.

The broader trend aligns with findings from Verizon DBIR and Mandiant M-Trends: attackers increasingly target network-edge devices where authentication is weak or absent.

Vulnerability classes this month command injection, memory corruption, and out-of-bounds access are consistent with this attack surface.

The key takeaway is that CVSS scoring alone is insufficient for prioritization. A remotely reachable, unauthenticated vulnerability with moderate scoring often presents higher real-world risk than a critical vulnerability requiring local access.

Organizations must prioritize based on exposure, exploit activity, and asset criticality. In practice, this means continuously answering two questions: which vulnerable devices are deployed, and how accessible they are from untrusted networks.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist



Source link