New InfraTrust report reveals infrastructure flaws admins should patch first
10 mins read

New InfraTrust report reveals infrastructure flaws admins should patch first

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.

The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw’s exploitability, exposure, and real-world risk rather than severity scores alone.

The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.

The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.

The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.

In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.

What to patch first

The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.

Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.

AdvisoryWhy patch now?
SonicWall SMA1000Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance.
Fortinet FortiSandboxTwo flaws later added to CISA KEV-listed that allow unauthenticated command injection.
Dell Networking (EMC Networking OS10 / SmartFabric Manager)Critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management.
F5 BIG-IPUnauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers.
JuniperRemotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions.
NVIDIA BlueField / ConnectXVulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.

In SonicWall’s case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA’s KEV catalog on July 16, after exploitation was detected.

While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.

“These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,” explains Eclypsium.

The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.

The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.

The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.

The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. 

Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.

As an example, HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.

While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.

July 2026 infrastructure reference

Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.

The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

VendorProductAdvisorySeverityExploitedWhy it matters
SonicWallSMA1000 remote-access applianceSNWLID-2026-0008Critical, 10.0YesActively exploited pre-auth RCE chain; CVSS 10.0.
DellEMC Networking OS10DSA-2026-240Critical, 9.8YesIncludes a CISA-listed exploited Linux flaw.
DellSmartFabric ManagerDSA-2026-317Critical, 9.8NoCritical flaws in data-center fabric management.
F5BIG-IP and F5 productsK000161837Critical, 9.2NoUnauthenticated memory-safety flaws on internet-facing ADCs.
LenovoThinkSystem and System x serversLEN-203310Critical, 9.0NoCode execution on server DPUs and SmartNICs.
NVIDIABlueField and ConnectXBulletin 5699Critical, 9.0NoCode execution on networking silicon in the data path.
QualcommSnapdragon and networking chipsetsJuly 2026 BulletinHigh, 8.8NoOEM-dependent fixes extend the exposure window.
JuniperJunos OS (MX and SRX)JSA110083High, 8.7NoRemote unauthenticated DoS against MX and SRX routers.
JuniperJunos OS (MX and SRX)JSA110086High, 8.7NoRemote unauthenticated DoS through the SIP ALG.
FortinetFortiSandboxFG-IR-26-145High, 8.6NoUnauthenticated VNC access on all network interfaces.
CitrixNetScaler ADC (Secure Access client)CTX696734High, 8.5NoClient flaws in the NetScaler remote-access stack.
DellPowerProtect Data Manager (DM5500)DSA-2026-282High, 8.5NoCommand injection and data exposure on a backup appliance.
HPPoly Voice (CCX, Trio, Edge E)HPSBPY04096High, 8.2NoMalicious SIP server can disable Poly Voice phones.
JuniperJunos OS Evolved (PTX)JSA110073High, 8.2NoRemote unauthenticated DoS against PTX core routers.
JuniperJunos OS (MX and SRX)JSA110082High, 8.2NoCrafted responses can crash the packet-forwarding engine.
JuniperJunos OS (SRX)JSA110090High, 8.2NoRemote unauthenticated crash in SRX packet processing.
DelliDRAC9 (PowerEdge BMC)DSA-2026-312High, 7.8NoBMC flaws affect control beneath the operating system.
HPHP PC BIOS (InsydeH2O tools)HPSBHF04134High, 7.8NoFirmware-update flaw can lead to code execution.
HPPoly Studio X video codecsHPSBPY04106High, 7.8YesRe-ships a CISA-listed exploited Qualcomm flaw.
CiscoCatalyst Centercisco-sa-catc-file-readHigh, 7.5NoUnauthenticated arbitrary file read from Catalyst Center.
CiscoSecure Web Appliancecisco-sa-clamavHigh, 7.5NoClamAV flaw can disable malware scanning.
DelliDRAC10 (PowerEdge BMC)DSA-2026-270High, 7.5NoBMC resource-exhaustion and certificate-validation flaws.
DellPowerEdge (OpenSSL)DSA-2026-316High, 7.5NoOpenSSL fixes reach servers only through Dell firmware.
Palo AltoPAN-OS (User-ID TSA)CVE-2026-0288High, 7.2NoUnauthenticated DoS and possible code execution.
HPHP PC BIOS (AMD Client UEFI)HPSBHF04133High, 7.1NoFirmware flaws can allow code execution below the OS.
JuniperJunos OS (RPD, BGP)JSA110076High, 7.1NoMalformed BGP updates can disrupt the routing control plane.
JuniperJunos OS (MX)JSA110079High, 7.1NoAdjacent attacker can stall packet processing.
JuniperJunos OS (QFX10000)JSA110080High, 7.1NoCrafted multicast traffic can degrade EVPN-VXLAN switches.
JuniperJunos OS (EX Virtual Chassis)JSA110087High, 7.1NosFlow memory leak can exhaust Virtual Chassis switches.
JuniperJunos OS (EX)JSA110092High, 7.1NoLow-privileged user can crash a switch line card.
LenovoLenovo PC BIOSLEN-220440High, 7.0NoBIOS memory-corruption flaws require OEM updates.
JuniperJunos OS EvolvedJSA110078Medium, 6.9NoUnexpectedly exposed internal service enables remote attacks.
JuniperJunos OS (SRX RA-VPN)JSA110081Medium, 6.9NoPre-auth VPN requests can crash the gatekeeper process.
JuniperJunos OS (MX and SRX, IKE)JSA110084Medium, 6.9NoFailed IKE negotiations can deny new VPN connections.
JuniperJunos OS EvolvedJSA110088Medium, 6.9NoRemote attacker can exhaust licenses and degrade service.
JuniperJunos OS (MX)JSA110093Medium, 6.9NoURL-parsing flaw can bypass web-filtering controls.
JuniperJunos OS (EX)JSA110077Medium, 6.8NoLocal user can stop all switch traffic.
JuniperJunos OS (EX, QFX, MX)JSA110085Medium, 6.8NoLow-privileged command can crash Layer 2 services.
FortinetFortiOS, FortiProxyFG-IR-26-148Medium, 6.6NoAuthenticated buffer overflow in firewall log reporting.
Palo AltoPAN-OSCVE-2026-0287Medium, 6.6NoUnauthenticated traffic can force the firewall into maintenance mode.
HPE Aruba NetworkingInstant On switchesHPESBNW05038Medium, 6.5NoUnauthenticated disclosure of cryptographic secrets.
NetgearNighthawk, Orbi, WAX routersPSV-000070859Medium, 6.3NoEdge-device command injection and stack-overflow flaws.
FortinetFortiOS, FortiProxyFG-IR-26-150Medium, 6.1NoPre-auth XSS can target administrator sessions.
HPPoly VoiceHPSBPY04109Medium, 6.0NoStolen cookie can be used to modify phone settings.
JuniperJunos OS Evolved (QFX)JSA110089Medium, 6.0NosFlow synchronization flaw can intermittently crash QFX switches.
Palo AltoPAN-OSCVE-2026-0286Medium, 6.0NoCompromised admin account can execute commands as root.
HPPoly VoiceHPSBPY04108Medium, 5.9NoStored XSS through attacker-controlled phone configuration.
Palo AltoPrisma Access Agent (iOS)CVE-2026-0277Medium, 5.7NoCertificate-validation flaw enables VPN interception.
FortinetFortiOS, FortiProxyFG-IR-26-151Medium, 5.5NoPrivileged path traversal can delete the root filesystem.
JuniperJunos OS (SNMP)JSA110074Medium, 5.3NoCrafted SNMPv3 queries can crash device monitoring.
Palo AltoPAN-OS (LSVPN)CVE-2026-0284Medium, 4.7NoUnauthenticated XML injection in Large Scale VPN.
Palo AltoPAN-OS (management)CVE-2026-0285Medium, 4.7NoAdmin SSRF can reach internal services.
Palo AltoPAN-OS (LSVPN)CVE-2026-0283Medium, 4.5NoAuthentication bypass can create an unauthorized VPN tunnel.
FortinetFortiOS, FortiProxyFG-IR-26-152Medium, 4.3NoPre-auth response splitting in the Web Filter portal.
FortinetFortiOS, FortiProxyFG-IR-26-153Medium, 4.3NoPre-auth response splitting in the captive portal.
FortinetFortiOS, FortiProxyFG-IR-26-154Medium, 4.3NoCaptive-portal memory disclosure may aid exploit chains.
Palo AltoPAN-OS (management)CVE-2026-0282Low, 2.7NoUnauthenticated temporary-file deletion on management interface.
Palo AltoPAN-OS (management)CVE-2026-0281Low, 2.1NoMalicious link can expose an administrator session token.
Palo AltoPAN-OS (dataplane)CVE-2026-0280Low, 1.7NoIPv6 flaw can bypass firewall policy.
Palo AltoPAN-OS (GlobalProtect, Captive Portal)CVE-2026-0279Low, 1.3NoPre-auth XSS in GlobalProtect and Captive Portal.
Palo AltoCortex XDR Broker VMCVE-2026-0276Low, 1.1NoLocal privilege escalation to root on Broker VM.

Leave a Reply

Your email address will not be published. Required fields are marked *