New InfraTrust report reveals infrastructure flaws admins should patch first

4 hours ago 5

InfraTrust

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.

The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone.

The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.

image

The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.

The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.

In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.

What to patch first

The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.

Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.

Advisory Why patch now?
SonicWall SMA1000 Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance.
Fortinet FortiSandbox Two flaws later added to CISA KEV-listed that allow unauthenticated command injection.
Dell Networking (EMC Networking OS10 / SmartFabric Manager) Critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management.
F5 BIG-IP Unauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers.
Juniper Remotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions.
NVIDIA BlueField / ConnectX Vulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.

In SonicWall's case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA's KEV catalog on July 16, after exploitation was detected.

While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.

"These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04," explains Eclypsium.

The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.

The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.

The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.

The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. 

Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.

As an example, HP's Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.

While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.

July 2026 infrastructure reference

Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.

The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

Vendor Product Advisory Severity Exploited Why it matters
SonicWall SMA1000 remote-access appliance SNWLID-2026-0008 Critical, 10.0 Yes Actively exploited pre-auth RCE chain; CVSS 10.0.
Dell EMC Networking OS10 DSA-2026-240 Critical, 9.8 Yes Includes a CISA-listed exploited Linux flaw.
Dell SmartFabric Manager DSA-2026-317 Critical, 9.8 No Critical flaws in data-center fabric management.
F5 BIG-IP and F5 products K000161837 Critical, 9.2 No Unauthenticated memory-safety flaws on internet-facing ADCs.
Lenovo ThinkSystem and System x servers LEN-203310 Critical, 9.0 No Code execution on server DPUs and SmartNICs.
NVIDIA BlueField and ConnectX Bulletin 5699 Critical, 9.0 No Code execution on networking silicon in the data path.
Qualcomm Snapdragon and networking chipsets July 2026 Bulletin High, 8.8 No OEM-dependent fixes extend the exposure window.
Juniper Junos OS (MX and SRX) JSA110083 High, 8.7 No Remote unauthenticated DoS against MX and SRX routers.
Juniper Junos OS (MX and SRX) JSA110086 High, 8.7 No Remote unauthenticated DoS through the SIP ALG.
Fortinet FortiSandbox FG-IR-26-145 High, 8.6 No Unauthenticated VNC access on all network interfaces.
Citrix NetScaler ADC (Secure Access client) CTX696734 High, 8.5 No Client flaws in the NetScaler remote-access stack.
Dell PowerProtect Data Manager (DM5500) DSA-2026-282 High, 8.5 No Command injection and data exposure on a backup appliance.
HP Poly Voice (CCX, Trio, Edge E) HPSBPY04096 High, 8.2 No Malicious SIP server can disable Poly Voice phones.
Juniper Junos OS Evolved (PTX) JSA110073 High, 8.2 No Remote unauthenticated DoS against PTX core routers.
Juniper Junos OS (MX and SRX) JSA110082 High, 8.2 No Crafted responses can crash the packet-forwarding engine.
Juniper Junos OS (SRX) JSA110090 High, 8.2 No Remote unauthenticated crash in SRX packet processing.
Dell iDRAC9 (PowerEdge BMC) DSA-2026-312 High, 7.8 No BMC flaws affect control beneath the operating system.
HP HP PC BIOS (InsydeH2O tools) HPSBHF04134 High, 7.8 No Firmware-update flaw can lead to code execution.
HP Poly Studio X video codecs HPSBPY04106 High, 7.8 Yes Re-ships a CISA-listed exploited Qualcomm flaw.
Cisco Catalyst Center cisco-sa-catc-file-read High, 7.5 No Unauthenticated arbitrary file read from Catalyst Center.
Cisco Secure Web Appliance cisco-sa-clamav High, 7.5 No ClamAV flaw can disable malware scanning.
Dell iDRAC10 (PowerEdge BMC) DSA-2026-270 High, 7.5 No BMC resource-exhaustion and certificate-validation flaws.
Dell PowerEdge (OpenSSL) DSA-2026-316 High, 7.5 No OpenSSL fixes reach servers only through Dell firmware.
Palo Alto PAN-OS (User-ID TSA) CVE-2026-0288 High, 7.2 No Unauthenticated DoS and possible code execution.
HP HP PC BIOS (AMD Client UEFI) HPSBHF04133 High, 7.1 No Firmware flaws can allow code execution below the OS.
Juniper Junos OS (RPD, BGP) JSA110076 High, 7.1 No Malformed BGP updates can disrupt the routing control plane.
Juniper Junos OS (MX) JSA110079 High, 7.1 No Adjacent attacker can stall packet processing.
Juniper Junos OS (QFX10000) JSA110080 High, 7.1 No Crafted multicast traffic can degrade EVPN-VXLAN switches.
Juniper Junos OS (EX Virtual Chassis) JSA110087 High, 7.1 No sFlow memory leak can exhaust Virtual Chassis switches.
Juniper Junos OS (EX) JSA110092 High, 7.1 No Low-privileged user can crash a switch line card.
Lenovo Lenovo PC BIOS LEN-220440 High, 7.0 No BIOS memory-corruption flaws require OEM updates.
Juniper Junos OS Evolved JSA110078 Medium, 6.9 No Unexpectedly exposed internal service enables remote attacks.
Juniper Junos OS (SRX RA-VPN) JSA110081 Medium, 6.9 No Pre-auth VPN requests can crash the gatekeeper process.
Juniper Junos OS (MX and SRX, IKE) JSA110084 Medium, 6.9 No Failed IKE negotiations can deny new VPN connections.
Juniper Junos OS Evolved JSA110088 Medium, 6.9 No Remote attacker can exhaust licenses and degrade service.
Juniper Junos OS (MX) JSA110093 Medium, 6.9 No URL-parsing flaw can bypass web-filtering controls.
Juniper Junos OS (EX) JSA110077 Medium, 6.8 No Local user can stop all switch traffic.
Juniper Junos OS (EX, QFX, MX) JSA110085 Medium, 6.8 No Low-privileged command can crash Layer 2 services.
Fortinet FortiOS, FortiProxy FG-IR-26-148 Medium, 6.6 No Authenticated buffer overflow in firewall log reporting.
Palo Alto PAN-OS CVE-2026-0287 Medium, 6.6 No Unauthenticated traffic can force the firewall into maintenance mode.
HPE Aruba Networking Instant On switches HPESBNW05038 Medium, 6.5 No Unauthenticated disclosure of cryptographic secrets.
Netgear Nighthawk, Orbi, WAX routers PSV-000070859 Medium, 6.3 No Edge-device command injection and stack-overflow flaws.
Fortinet FortiOS, FortiProxy FG-IR-26-150 Medium, 6.1 No Pre-auth XSS can target administrator sessions.
HP Poly Voice HPSBPY04109 Medium, 6.0 No Stolen cookie can be used to modify phone settings.
Juniper Junos OS Evolved (QFX) JSA110089 Medium, 6.0 No sFlow synchronization flaw can intermittently crash QFX switches.
Palo Alto PAN-OS CVE-2026-0286 Medium, 6.0 No Compromised admin account can execute commands as root.
HP Poly Voice HPSBPY04108 Medium, 5.9 No Stored XSS through attacker-controlled phone configuration.
Palo Alto Prisma Access Agent (iOS) CVE-2026-0277 Medium, 5.7 No Certificate-validation flaw enables VPN interception.
Fortinet FortiOS, FortiProxy FG-IR-26-151 Medium, 5.5 No Privileged path traversal can delete the root filesystem.
Juniper Junos OS (SNMP) JSA110074 Medium, 5.3 No Crafted SNMPv3 queries can crash device monitoring.
Palo Alto PAN-OS (LSVPN) CVE-2026-0284 Medium, 4.7 No Unauthenticated XML injection in Large Scale VPN.
Palo Alto PAN-OS (management) CVE-2026-0285 Medium, 4.7 No Admin SSRF can reach internal services.
Palo Alto PAN-OS (LSVPN) CVE-2026-0283 Medium, 4.5 No Authentication bypass can create an unauthorized VPN tunnel.
Fortinet FortiOS, FortiProxy FG-IR-26-152 Medium, 4.3 No Pre-auth response splitting in the Web Filter portal.
Fortinet FortiOS, FortiProxy FG-IR-26-153 Medium, 4.3 No Pre-auth response splitting in the captive portal.
Fortinet FortiOS, FortiProxy FG-IR-26-154 Medium, 4.3 No Captive-portal memory disclosure may aid exploit chains.
Palo Alto PAN-OS (management) CVE-2026-0282 Low, 2.7 No Unauthenticated temporary-file deletion on management interface.
Palo Alto PAN-OS (management) CVE-2026-0281 Low, 2.1 No Malicious link can expose an administrator session token.
Palo Alto PAN-OS (dataplane) CVE-2026-0280 Low, 1.7 No IPv6 flaw can bypass firewall policy.
Palo Alto PAN-OS (GlobalProtect, Captive Portal) CVE-2026-0279 Low, 1.3 No Pre-auth XSS in GlobalProtect and Captive Portal.
Palo Alto Cortex XDR Broker VM CVE-2026-0276 Low, 1.1 No Local privilege escalation to root on Broker VM.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read Entire Article