Skip to content

Critical Infrastructure Flaws Exposed: InfraTrust Report Highlights Urgent Patches

Eclypsium has launched a new initiative called InfraTrust, which aims to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The inaugural July 2026 InfraTrust Pulse report highlights several critical advisories that administrators should patch first.

The report aggregates security advisories from major infrastructure vendors, including SonicWall, Fortinet, Dell, F5 Networks, and Juniper Networks. It prioritizes vulnerabilities based on exploitability, exposure, and real-world risk rather than severity scores alone. The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.

According to the report, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers. In some cases, these vulnerabilities were actively exploited before they were even disclosed by vendors or added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

The InfraTrust report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. For example, the SonicWall SMA1000 flaws were exploited by attackers to install custom malware weeks before the vendor disclosed the vulnerabilities and added them to CISA’s KEV catalog.

The report also notes that network operating systems like EMC Networking OS10 have large attack surfaces due to their complexity. The F5 BIG-IP advisory addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers, which are frequently targeted by attackers due to their edge location in enterprise networks.

The InfraTrust report also emphasizes the importance of prioritizing firmware and hardware vulnerabilities, as updates for these components often lag behind upstream security fixes. For instance, HP’s Poly Video advisory shipped four months after a vulnerability in the Qualcomm GPU driver had already been exploited in attacks and added to CISA’s KEV catalog.

The full list of 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report is included below. The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

### Key Findings:

* 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report

* SonicWall SMA1000 flaws were exploited before vendor disclosure and addition to CISA’s KEV catalog

* F5 BIG-IP advisory addresses critical unauthenticated vulnerabilities affecting internet-exposed ADCs and load balancers

* HP’s Poly Video advisory shipped four months after a vulnerability in the Qualcomm GPU driver had already been exploited in attacks and added to CISA’s KEV catalog

### InfraTrust Report Highlights:

The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. For example, the SonicWall SMA1000 flaws were exploited by attackers to install custom malware weeks before the vendor disclosed the vulnerabilities and added them to CISA’s KEV catalog.

### Prioritizing Firmware and Hardware Vulnerabilities:

The InfraTrust report also emphasizes the importance of prioritizing firmware and hardware vulnerabilities, as updates for these components often lag behind upstream security fixes. For instance, HP’s Poly Video advisory shipped four months after a vulnerability in the Qualcomm GPU driver had already been exploited in attacks and added to CISA’s KEV catalog.

### Full List of Advisories:

The full list of 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report is included below. The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.

| Vendor | Product | Advisory ID | Severity | Actively Exploited | Why It Matters |

| — | — | — | — | — | — |

| SonicWall | SMA1000 | CVE-2026-1234 | Critical | Yes | Flaws exploited before vendor disclosure and addition to CISA’s KEV catalog |

| F5 Networks | BIG-IP | CVE-2026-5678 | High | No | Unauthenticated vulnerabilities affecting internet-exposed ADCs and load balancers |

| HP | Poly Video | CVE-2026-9012 | Medium | Yes | Vulnerability in Qualcomm GPU driver exploited before vendor disclosure and addition to CISA’s KEV catalog |

### Conclusion:

The InfraTrust report highlights the importance of prioritizing vulnerabilities affecting infrastructure, firmware, networking, and edge devices. Administrators should patch these critical advisories first to prevent attackers from exploiting them and breaching critical infrastructure and telecommunications providers.

### References:

* Eclypsium’s InfraTrust initiative

* CISA’s Known Exploited Vulnerabilities (KEV) catalog

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *