In its inaugural July 2026 InfraTrust Pulse, Eclypsium tracked 61 infrastructure advisories from 14 vendors — including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
InfraTrust Pulse: what Eclypsium measured and why
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and a monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities that affect infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights which vulnerabilities administrators should prioritize based on exploitability, exposure, and real-world risk rather than severity scores alone.
Top advisories administrators should patch first
The report names specific advisories and CVEs that Eclypsium says require urgent attention because they are internet-exposed, already exploited, or remotely exploitable without authentication. Examples singled out in July 2026 include:
- SonicWall SMA1000 flaws tracked as CVE-2026-15409 and CVE-2026-15410 — Eclypsium reports attackers were exploiting these flaws to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
- Fortinet FortiSandbox advisories FG-IR-26-100 and FG-IR-26-141, which contain critical command injection vulnerabilities CVE-2026-39808 and CVE-2026-25089 — Eclypsium notes these were disclosed in April and June 2026 and added to CISA’s KEV catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04.
- Dell advisories DSA-2026-240 and DSA-2026-317 addressing critical flaws in EMC Networking OS10 and SmartFabric Manager — Eclypsium calls out OS10 for containing hundreds of upstream fixes, illustrating that network operating systems can be large Linux-like distributions with broad attack surfaces.
- F5 BIG-IP advisory K000153397 covering critical unauthenticated vulnerabilities in internet-exposed application delivery controllers (ADCs) and load balancers, devices that frequently sit at the enterprise network edge.
- Juniper advisories JSA110083 and JSA110086 for remotely exploitable Junos OS flaws that can crash routers and switches and potentially disrupt availability.
- NVIDIA Security Bulletin 5865 covering vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.
Firmware and hardware updates lag — HP Poly example
Eclypsium also highlighted firmware and hardware problems, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them. As an example, the report notes HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability, CVE-2026-21385, had already been exploited and added to CISA’s KEV catalog.
Exploitability, reachability, and exposure over CVSS scores
Rather than counting individual CVEs, InfraTrust tracks vendor advisories, reasoning that a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities. The July report contains six critical advisories but identifies 26 vulnerabilities that can be exploited remotely without authentication. Eclypsium emphasizes that an internet-reachable flaw with a lower CVSS score may present a greater operational risk than a higher-scoring vulnerability that requires local administrator access.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: prioritize internet-exposed infrastructure and unauthenticated remote vectors first, paying particular attention to advisories named by Eclypsium — SonicWall CVE-2026-15409/15410, Fortinet CVE-2026-39808/25089, F5 K000153397, Juniper JSA110083/JSA110086, and the Dell and NVIDIA advisories.
- Policymakers and regulators: note that CISA added the two Fortinet CVEs to the KEV catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04, illustrating how federal guidance can impose rapid remediation timelines for known exploited flaws.
- Affected enterprises and procurement leaders: track vendor advisories rather than relying solely on CVE counts, and factor in that network operating system advisories — such as Dell’s OS10 advisory — may bundle hundreds of upstream fixes requiring coordinated firmware and software updates.
The InfraTrust Pulse frames a simple operational choice: prioritize vulnerabilities by how easily they can be exploited and how exposed they are, not only by their severity score. That approach is driven by real-world evidence in the report — SonicWall flaws exploited before disclosure, Fortinet CVEs added to CISA’s KEV with a tight federal remediation deadline, and hardware driver flaws appearing in advisories months after they were exploited. Eclypsium’s inaugural monthly pulse thus sets a practical bar for defenders: treat internet-reachable, unauthenticated, and actively exploited advisories as emergency workstreams.
Read the original Eclypsium coverage at: https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/




