InfoSecNexus briefing

Live Network Security Brief for July 29, 2026: Edge Devices, VPNs, and Segmentation

Network defender inspecting a protected data connection

Current network security intelligence for edge appliances, routers, firewalls, VPNs, DNS, management planes, and segmentation controls.

Edge exposure view

Edge systems often combine public reachability with privileged access to internal networks. Inventory accuracy, supported firmware, restricted management paths, and independent logging are therefore central to response.

For July 29, 2026, the lead development is CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability. Start by confirming where Fortinet FortiOS is deployed, who owns it, and whether the affected path is reachable. The remaining items below add the product-specific context needed to turn the headline into an owned security decision.

Network and appliance developments

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CISA Known Exploited Vulnerabilities | July 27, 2026 | Known Exploited | Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Why it matters: Fortinet FortiOS commonly protects an internet edge or management boundary. Exposure there can affect remote access, traffic inspection, credentials, and the trust placed in downstream systems.

What to verify: Check the running firmware and model, restrict management access, compare configuration changes and new accounts, preserve independent logs, and rotate credentials if compromise cannot be excluded.

CISA remediation date: 2026-08-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Operational focus: Identify exposed management interfaces and confirm the exact firmware or software version.

Open the original CISA Known Exploited Vulnerabilities record

CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability

CISA Known Exploited Vulnerabilities | July 21, 2026 | Known Exploited | DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Why it matters: DD-WRT DD-WRT is a memory-safety issue whose practical impact depends on the reachable parser, process privileges, platform protections, and reliability of attacker-controlled input.

What to verify: Confirm the exact affected build and component exposure, update from the vendor channel, review crash and restart telemetry, and keep network containment in place until the fixed process is running.

CISA remediation date: 2026-07-24. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Operational focus: Restrict administrative access to trusted networks and rotate credentials after suspected compromise.

Open the original CISA Known Exploited Vulnerabilities record

CVE-2026-49447: Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

GitHub Advisory Database | July 29, 2026 | MEDIUM | CVSS 5.3 | GitHub Advisory Database github.com/azukaar/cosmos-server

### Summary `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty `Authorization` header. The handler strips the string `Bearer ` from the header but never validates the resulting token and never uses it in the database query. This was confirmed locally by routing a request through the real `tokenMiddleware` with `Authorization: Bearer not-a-real-token`. The…

Why it matters: GitHub Advisory Database github.com/azukaar/cosmos-server participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus