Network & InfrastructureBleeping Computer
10.0 — CRITICAL
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Russian and Chinese state-sponsored threat actors have targeted vulnerable network edge devices, exploiting flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers.
⚙️Technical Details
💥Impact Assessment
Severity: critical
Who Is at Risk
organizations with internet-exposed infrastructure, including critical infrastructure and telecommunications providers
🛡️Recommended Actions
1patch vulnerabilities in SonicWall SMA1000, Fortinet FortiSandbox, Dell Networking OS10 / SmartFabric Manager, F5 BIG-IP, Juniper Networks, NVIDIA BlueField / ConnectX immediately
2enable network segmentation and isolation to limit the spread of malware
3monitor network traffic for signs of suspicious activity
📦Affected Products
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200VFortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox PaasQualcomm 5G Fixed Wireless Access PlatformQualcomm 5G Fixed Wireless Access Platform Firmware
🔐NVD Verified DataVERIFIED
CVE-2026-15409 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-918
Affected Products (CPE)
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200V
CVE-2026-15410 ↗CVSS 7.2 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-94
Affected Products (CPE)
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200V
CVE-2026-39808 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Fortinet Fortisandbox
CVE-2026-25089 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas
CVE-2026-21385 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-190
Affected Products (CPE)
Qualcomm 5G Fixed Wireless Access PlatformQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Apq8098Qualcomm Apq8098 FirmwareQualcomm Ar8031
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
