[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGVfbMuLpZZDCcGp7j-UF6Catq1i3n8bB9jB4PgZ7yeE":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"aaaf0f02-b0d0-46c5-8b29-0cc98867591c","New InfraTrust report reveals infrastructure flaws admins should patch first","new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first-4bcb25","Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]","Eclypsium has released InfraTrust, a new cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities in infrastructure, firmware, networking, and edge devices. The inaugural July 2026 report tracked 61 infrastructure advisories from 14 vendors, identifying six critical and 26 remotely exploitable vulnerabilities, with emphasis on actively exploited flaws affecting internet-facing devices like routers, firewalls, and VPNs. The report highlights priorities including SonicWall SMA1000 (CVE-2026-15409, CVE-2026-15410), Fortinet FortiSandbox (CVE-2026-39808, CVE-2026-25089), and devices from Dell, F5, Juniper, and NVIDIA, noting that Russian and Chinese state-sponsored actors like Volt Typhoon and Salt Typhoon have exploited similar infrastructure flaws.","Eclypsium launches InfraTrust report prioritizing infrastructure vulnerabilities for patching.","New InfraTrust report reveals infrastructure flaws admins should patch first By Lawrence Abrams July 22, 2026 10:15 AM 0 Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone. The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog. Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone. The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices. In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon. What to patch first The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise. Advisory Why patch now? SonicWall SMA1000 Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance. Fortinet FortiSandbox Two flaws later added to CISA KEV-listed that allow unauthenticated command injection. Dell Networking (EMC Networking OS10 \u002F SmartFabric Manager) Critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management. F5 BIG-IP Unauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers. Juniper Remotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions. NVIDIA BlueField \u002F ConnectX Vulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. In SonicWall's case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The Fortinet FortiSandbox advisories (FG-IR-26-100 \u002F FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA's KEV catalog on July 16, after exploitation was detected. While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks. \"These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,\" explains Eclypsium. The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces. The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers. The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability. The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them. As an example, HP's Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities. While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access. July 2026 infrastructure reference Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report. The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters. Vendor Product Advisory Severity Exploited Why it matters SonicWall SMA1000 remote-access appliance SNWLID-2026-0008 Critical, 10.0 Yes Actively exploited pre-auth RCE chain; CVSS 10.0. Dell EMC Networking OS10 DSA-2026-240 Critical, 9.8 Yes Includes a CISA-listed exploited Linux flaw. Dell SmartFabric Manager DSA-2026-317 Critical, 9.8 No Critical flaws in data-center fabric management. F5 BIG-IP and F5 products K000161837 Critical, 9.2 No Unauthenticated memory-safety flaws on internet-facing ADCs. Lenovo ThinkSystem and System x servers LEN-203310 Critical, 9.0 No Code execution on server DPUs and SmartNICs. NVIDIA BlueField and ConnectX Bulletin 5699 Critical, 9.0 No Code execution on networking silicon in the data path. Qualcomm Snapdragon and networking chipsets July 2026 Bulletin High, 8.8 No OEM-dependent fixes extend the exposure window. Juniper Junos OS (MX and SRX) JSA110083 High, 8.7 No Remote unauthenticated DoS against MX and SRX routers. Juniper Junos OS (MX and SRX) JSA110086 High, 8.7 No Remote unauthenticated DoS through the SIP ALG. Fortinet FortiSandbox FG-IR-26-145 High, 8.6 No Unauthenticated VNC access on all network interfaces. Citrix NetScaler ADC (Secure Access client) CTX696734 High, 8.5 No Client flaws in the NetScaler remote-access stack. Dell PowerProtect Data Manager (DM5500) DSA-2026-282 High, 8.5 No Command injection and data exposure on a backup appliance. HP Poly Voice (CCX, Trio, Edge E) HPSBPY04096 High, 8.2 No Malicious SIP server can disable Poly Voice phones. Juniper Junos OS Evolved (PTX) JSA110073 High, 8.2 No Remote unauthenticated DoS against PTX core routers. Juniper Junos OS (MX and SRX) JSA110082 High, 8.","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F21\u002Finfratrust.jpg","2026-07-22T14:15:00+00:00","2026-07-22T16:00:12.65061+00:00",7,[18,21,24,26,28,30],{"name":19,"type":20},"Eclypsium","vendor",{"name":22,"type":23},"InfraTrust","product",{"name":25,"type":23},"InfraTrust Pulse",{"name":27,"type":23},"SonicWall SMA1000",{"name":29,"type":23},"Fortinet FortiSandbox",{"name":31,"type":23},"F5 BIG-IP","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,48],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[54,58,60,63],{"type":55,"value":56,"context":57},"cve","CVE-2026-15409","SonicWall SMA1000 actively exploited vulnerability",{"type":55,"value":59,"context":57},"CVE-2026-15410",{"type":55,"value":61,"context":62},"CVE-2026-39808","Fortinet FortiSandbox command injection, listed in CISA KEV",{"type":55,"value":64,"context":62},"CVE-2026-25089"]