AI & TechBusinessCybersecurityNewswireTechnology

InfraTrust Report: Admins Must Patch These Flaws First

Originally published on: July 23, 2026
▼ Summary

– Eclypsium launched InfraTrust, a cybersecurity knowledge base and monthly Pulse report that helps organizations prioritize infrastructure vulnerabilities based on exploitability, exposure, and real-world risk rather than CVSS scores alone.
– The inaugural July 2026 InfraTrust Pulse tracked 61 advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
– The report highlights that Russian and Chinese state-sponsored groups increasingly target vulnerable network edge devices, and that attackers exploited SonicWall SMA1000 flaws to install malware before disclosure.
– Eclypsium prioritized advisories for SonicWall, Fortinet, Dell, F5, Juniper, and NVIDIA due to active exploitation, internet exposure, or remote compromise risk.
– The report notes firmware updates often lag behind upstream fixes, exemplified by HP’s Poly Video advisory shipping an already exploited Qualcomm GPU driver four months late.

Eclypsium has introduced InfraTrust, a new infrastructure cybersecurity knowledge base paired with a monthly InfraTrust Pulse report, aimed at helping organizations prioritize vulnerabilities in infrastructure, firmware, networking, and edge devices. Rather than relying solely on severity scores, this monthly report aggregates security advisories from major infrastructure vendors and highlights the flaws administrators should address based on exploitability, exposure, and real-world risk.

The inaugural July 2026 InfraTrust Pulse, authored by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors. Among these, six were classified as critical, and 26 vulnerabilities were remotely exploitable without authentication. The report also flags several advisories containing actively exploited flaws or those already listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Eclypsium argues that organizations should shift their focus from CVSS scores alone to a more practical assessment of exploitability, reachability, and exposure. This emphasis on infrastructure security comes at a critical time, as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices. In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including campaigns attributed to groups like Volt Typhoon and Salt Typhoon.

What to Patch First

The report identifies several advisories that administrators should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. Below are the key advisories Eclypsium recommends patching immediately:

  • SonicWall SMA1000: Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance.In the SonicWall case, attackers were exploiting the SMA1000 flaws,tracked as CVE-2026-15409 and CVE-2026-15410,to install custom malware weeks before SonicWall disclosed them and before they were added to CISA’s KEV catalog.The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities, CVE-2026-39808 and CVE-2026-25089. While disclosed in April and June 2026, they were added to CISA’s KEV catalog on July 16, after exploitation was detected. Eclypsium included these despite them falling outside the 30-day reporting window because organizations may not have patched them or realized they were exposed. “These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,” explains Eclypsium.The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets.The Juniper Networks advisories (JSA110083 and JSA110086) address remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.Eclypsium also flagged firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them. For example, HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited and added to CISA’s KEV catalog.Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities. While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk than a higher-scoring vulnerability requiring local admin access.

July 2026 Infrastructure Reference

Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in the inaugural July 2026 InfraTrust Pulse report. The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

| Vendor | Product | Advisory | Severity | Exploited | Why it matters | |——–|———|———-|———-|———–|—————-| | SonicWall | SMA1000 remote-access appliance | SNWLID-2026-0008 | Critical, 10.0 | Yes | Actively exploited pre-auth RCE chain; CVSS 10.0. | | Dell | EMC Networking OS10 | DSA-2026-240 | Critical, 9.8 | Yes | Includes a CISA-listed exploited Linux flaw. | | Dell | SmartFabric Manager | DSA-2026-317 | Critical, 9.8 | No | Critical flaws in data-center fabric management. | | F5 | BIG-IP and F5 products | K000161837 | Critical, 9.2 | No | Unauthenticated memory-safety flaws on internet-facing ADCs. | | Lenovo | ThinkSystem and System x servers | LEN-203310 | Critical, 9.0 | No | Code execution on server DPUs and SmartNICs. | | NVIDIA | BlueField and ConnectX | Bulletin 5699 | Critical, 9.0 | No | Code execution on networking silicon in the data path. | | Qualcomm | Snapdragon and networking chipsets | July 2026 Bulletin | High, 8.8 | No | OEM-dependent fixes extend the exposure window. | | Juniper | Junos OS (MX and SRX) | JSA110083 | High, 8.7 | No | Remote unauthenticated DoS against MX and SRX routers.

| | Juniper | Junos OS (MX and SRX) | JSA110086 | High, 8.7 | No | Remote unauthenticated DoS through the SIP ALG. | | Fortinet | FortiSandbox | FG-IR-26-145 | High, 8.6 | No | Unauthenticated VNC access on all network interfaces. | | Citrix | NetScaler ADC (Secure Access client) | CTX696734 | High, 8.5 | No | Client flaws in the NetScaler remote-access stack. | | Dell | PowerProtect Data Manager (DM5500) | DSA-2026-282 | High, 8.5 | No | Command injection and data exposure on a backup appliance. | | HP | Poly Voice (CCX, Trio, Edge E) | HPSBPY04096 | High, 8.2 | No | Malicious SIP server can disable Poly Voice phones. | | Juniper | Junos OS Evolved (PTX) | JSA110073 | High, 8.2 | No | Remote unauthenticated DoS against PTX core routers. | | Juniper | Junos OS (MX and SRX) | JSA110082 | High, 8.2 | No | Crafted responses can crash the packet-forwarding engine. | | Juniper | Junos OS (SRX) | JSA110090 | High, 8.2 | No | Remote unauthenticated crash in SRX packet processing. | | Dell | iDRAC9 (PowerEdge BMC) | DSA-2026-312 | High, 7.8 | No | BMC flaws affect control beneath the operating system.

| | HP | HP PC BIOS (InsydeH2O tools) | HPSBHF04134 | High, 7.8 | No | Firmware-update flaw can lead to code execution. | | HP | Poly Studio X video codecs | HPSBPY04106 | High, 7.8 | Yes | Re-ships a CISA-listed exploited Qualcomm flaw. | | Cisco | Catalyst Center | cisco-sa-catc-file-read | High, 7.5 | No | Unauthenticated arbitrary file read from Catalyst Center. | | Cisco | Secure Web Appliance | cisco-sa-clamav | High, 7.5 | No | ClamAV flaw can disable malware scanning. | | Dell | iDRAC10 (PowerEdge BMC) | DSA-2026-270 | High, 7.5 | No | BMC resource-exhaustion and certificate-validation flaws. | | Dell | PowerEdge (OpenSSL) | DSA-2026-316 | High, 7.5 | No | OpenSSL fixes reach servers only through Dell firmware. | | Palo Alto | PAN-OS (User-ID TSA) | CVE-2026-0288 | High, 7.2 | No | Unauthenticated DoS and possible code execution. | | HP | HP PC BIOS (AMD Client UEFI) | HPSBHF04133 | High, 7.1 | No | Firmware flaws can allow code execution below the OS. | | Juniper | Junos OS (RPD, BGP) | JSA110076 | High, 7.1 | No | Malformed BGP updates can disrupt the routing control plane.

| | Juniper | Junos OS (MX) | JSA110079 | High, 7.1 | No | Adjacent attacker can stall packet processing. | | Juniper | Junos OS (QFX10000) | JSA110080 | High, 7.1 | No | Crafted multicast traffic can degrade EVPN-VXLAN switches. | | Juniper | Junos OS (EX Virtual Chassis) | JSA110087 | High, 7.1 | No | sFlow memory leak can exhaust Virtual Chassis switches. | | Juniper | Junos OS (EX) | JSA110092 | High, 7.1 | No | Low-privileged user can crash a switch line card. | | Lenovo | Lenovo PC BIOS | LEN-220440 | High, 7.0 | No | BIOS memory-corruption flaws require OEM updates. | | Juniper | Junos OS Evolved | JSA110078 | Medium, 6.9 | No | Unexpectedly exposed internal service enables remote attacks. | | Juniper | Junos OS (SRX RA-VPN) | JSA110081 | Medium, 6.9 | No | Pre-auth VPN requests can crash the gatekeeper process. | | Juniper | Junos OS (MX and SRX, IKE) | JSA110084 | Medium, 6.9 | No | Failed IKE negotiations can deny new VPN connections. | | Juniper | Junos OS Evolved | JSA110088 | Medium, 6.9 | No | Remote attacker can exhaust licenses and degrade service. | | Juniper | Junos OS (MX) | JSA110093 | Medium, 6.9 | No | URL-parsing flaw can bypass web-filtering controls.

| | Juniper | Junos OS (EX) | JSA110077 | Medium, 6.8 | No | Local user can stop all switch traffic. | | Juniper | Junos OS (EX, QFX, MX) | JSA110085 | Medium, 6.8 | No | Low-privileged command can crash Layer 2 services. | | Fortinet | FortiOS, FortiProxy | FG-IR-26-148 | Medium, 6.6 | No | Authenticated buffer overflow in firewall log reporting. | | Palo Alto | PAN-OS | CVE-2026-0287 | Medium, 6.6 | No | Unauthenticated traffic can force the firewall into maintenance mode. | | HPE | Aruba Networking Instant On switches | HPESBNW05038 | Medium, 6.5 | No | Unauthenticated disclosure of cryptographic secrets. | | Netgear | Nighthawk, Orbi, WAX routers | PSV-000070859 | Medium, 6.3 | No | Edge-device command injection and stack-overflow flaws. | | Fortinet | FortiOS, FortiProxy | FG-IR-26-150 | Medium, 6.1 | No | Pre-auth XSS can target administrator sessions. | | HP | Poly Voice | HPSBPY04109 | Medium, 6.0 | No | Stolen cookie can be used to modify phone settings. | | Juniper | Junos OS Evolved (QFX) | JSA110089 | Medium, 6.0 | No | sFlow synchronization flaw can intermittently crash QFX switches.

| | Palo Alto | PAN-OS | CVE-2026-0286 | Medium, 6.0 | No | Compromised admin account can execute commands as root. | | HP | Poly Voice | HPSBPY04108 | Medium, 5.9 | No | Stored XSS through attacker-controlled phone configuration. | | Palo Alto | Prisma Access Agent (iOS) | CVE-2026-0277 | Medium, 5.7 | No | Certificate-validation flaw enables VPN interception. | | Fortinet | FortiOS, FortiProxy | FG-IR-26-151 | Medium, 5.5 | No | Privileged path traversal can delete the root filesystem. | | Juniper | Junos OS (SNMP) | JSA110074 | Medium, 5.3 | No | Crafted SNMPv3 queries can crash device monitoring. | | Palo Alto | PAN-OS (LSVPN) | CVE-2026-0284 | Medium, 4.7 | No | Unauthenticated XML injection in Large Scale VPN. | | Palo Alto | PAN-OS (management) | CVE-2026-0285 | Medium, 4.7 | No | Admin SSRF can reach internal services. | | Palo Alto | PAN-OS (LSVPN) | CVE-2026-0283 | Medium, 4.5 | No | Authentication bypass can create an unauthorized VPN tunnel. | | Fortinet | FortiOS, FortiProxy | FG-IR-26-152 | Medium, 4.3 | No | Pre-auth response splitting in the Web Filter portal.

| | Fortinet | FortiOS, FortiProxy | FG-IR-26-153 | Medium, 4.3 | No | Pre-auth response splitting in the captive portal. | | Fortinet | FortiOS, FortiProxy | FG-IR-26-154 | Medium, 4.3 | No | Captive-portal memory disclosure may aid exploit chains. | | Palo Alto | PAN-OS (management) | CVE-2026-0282 | Low, 2.7 | No | Unauthenticated temporary-file deletion on management interface. | | Palo Alto | PAN-OS (management) | CVE-2026-0281 | Low, 2.1 | No | Malicious link can expose an administrator session token. | | Palo Alto | PAN-OS (dataplane) | CVE-2026-0280 | Low, 1.7 | No | IPv6 flaw can bypass firewall policy. | | Palo Alto | PAN-OS (GlobalProtect, Captive Portal) | CVE-2026-0279 | Low, 1.3 | No | Pre-auth XSS in GlobalProtect and Captive Portal. | | Palo Alto | Cortex XDR Broker VM | CVE-2026-0276 | Low, 1.1 | No | Local privilege escalation to root on Broker VM. |

(Source: BleepingComputer)

Topics

infrastructure vulnerabilities 98% vulnerability prioritization 95% active exploitation 92% network edge devices 90% state-sponsored threats 88% vendor advisories 87% remote code execution 85% cisa kev catalog 84% firmware security 82% patch management 81%