The July edition of Eclypsium’s newly launched InfraTrust Pulse report has quietly reframed how enterprises should think about infrastructure patching, and the numbers behind it deserve attention.
In the thirty days ending July 17, 2026, tracked vendors issued 61 in-scope security advisories across 14 vendors, with only six rated CVSS-critical, yet 26 of those advisories describe flaws exploitable remotely without any authentication.
Eclypsium, the infrastructure assurance company, built InfraTrust as a global hardware risk knowledge base and launched InfraTrust Pulse as its monthly companion digest, explicitly comparing the cadence to Microsoft’s Patch Tuesday but focused on the hardware layer: network devices, servers, chips, firmware, and baseboard management controllers.
61 Advisories, 26 Unauthenticated Flaws
The report deliberately counts advisories rather than raw CVE totals, since a single Dell EMC Networking OS10 update can bundle hundreds of upstream Linux CVEs that reflect Debian’s release cycle rather than actual infrastructure exposure.

The report’s top priority is SonicWall’s SMA1000 remote-access appliance, tied to advisory SNWLID-2026-0008, which pairs CVE-2026-15409, an unauthenticated SSRF flaw scoring a perfect CVSS 10.0, with CVE-2026-15410, a code-injection bug that together enable full remote code execution.
CISA added both to its Known Exploited Vulnerabilities catalog on July 14, giving federal agencies a BOD 26-04 deadline of July 17.
Attackers who breached unpatched appliances reportedly exfiltrated credentials, active session databases, and TOTP MFA seed configurations, meaning patched systems may still harbor compromised logins unless organizations also re-image affected devices, rotate all credentials, reset MFA seeds, and invalidate active sessions.
Fortinet’s FortiSandbox carries two unauthenticated OS command-injection flaws, CVE-2026-39808 and CVE-2026-25089, both added to the KEV catalog on July 16 with a July 19 remediation deadline.
Since FortiSandbox is designed to ingest attacker-supplied malware samples and holds service-account credentials, Eclypsium recommends treating any internet-reachable instance as compromised, patching to 4.4.9 or 5.0.6 or later, removing management interfaces from public exposure, and rotating every credential the appliance touched.
Two of the six critical advisories belong to Dell networking gear, DSA-2026-240 for EMC Networking OS10 and DSA-2026-317 for SmartFabric Manager, both scoring 9.8 and both unauthenticated.
The OS10 advisory also folds in CVE-2026-31431, the so-called “Dirty Frag” Linux kernel privilege-escalation bug added to KEV back in May.
F5 shipped an out-of-band BIG-IP advisory (CVSS 9.2) on July 15 affecting internet-facing load balancers, while Juniper contributed two unauthenticated denial-of-service bugs in Junos on MX and SRX Series devices.
A recurring theme is how slowly fixes trickle down through OEM supply chains. HP’s Poly Video advisory re-ships a Qualcomm KGSL GPU driver fix for CVE-2026-21385, a chipset flaw that CISA added to KEV back in March, four months before HP’s own bulletin appeared.
Lenovo separately re-issued NVIDIA’s BlueField and ConnectX out-of-bounds write fix under its own advisory number, underscoring how the same silicon vulnerability can surface multiple times across vendor ecosystems that share components.
Juniper (19 advisories) and Fortinet (7) topped the volume count this month, and Palo Alto added 12 mostly low-severity PAN-OS bulletins, reinforcing Eclypsium’s core argument: sort by internet exposure and reachability first, and let CVSS serve only as a tiebreaker.
That logic aligns with broader industry findings from Verizon’s DBIR and Mandiant’s M-Trends reports showing edge devices, firewalls, and remote-access gateways as the preferred entry points for real-world intrusions.