Skip to content
New InfraTrust report reveals infrastructure flaws admins should patch first

New InfraTrust report reveals infrastructure flaws admins should patch first

Bleepingcomputer Lawrence Abrams July 22, 2026

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.

The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone.

The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.

The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.

The focus on infrastructure security comes as Russian and Chinese state- threat actors have increasingly targeted vulnerable network edge devices.

In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers , including in campaigns attributed to state- hacking groups such as Volt Typhoon and Salt Typhoon.

The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.

Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.

In SonicWall's case, attackers were exploiting the SMA1000 flaws , tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

The Fortinet FortiSandbox advisories ( FG-IR-26-100 / FG-IR-26-141 ) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA's KEV catalog on July 16, after exploitation was detected .

While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.

"These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04," explains Eclypsium.

The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.

The F5 BIG-IP advisory ( K000153397 ) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.

The Juniper Networks advisory ( JSA110083 and JSA110086 ) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.

The NVIDIA advisory ( NVIDIA Security Bulletin 5865 ) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.

Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.

As an example, HP's Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.

While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.

Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.

The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.