• 2 min read
61 infrastructure advisories top July patch list
Eclypsium’s first InfraTrust Pulse tracks 61 advisories from 14 vendors and flags the flaws admins should patch first based on real-world risk.

Image: BleepingComputer
Eclypsium has launched InfraTrust, a new infrastructure security knowledge base paired with a monthly InfraTrust Pulse report meant to help organizations prioritize vulnerabilities in firmware, networking, infrastructure, and edge devices.
The first report, July 2026 InfraTrust Pulse, was authored by Paul Asadoorian, Principal Security Researcher at Eclypsium. It tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
Eclypsium’s core argument is that admins should not rely on CVSS scores alone. Instead, the company says patching decisions should weigh exploitability, reachability, and exposure, especially as Russian and Chinese state-backed groups have increasingly targeted routers, VPNs, firewalls, and other internet-facing devices. The report points to campaigns tied to Volt Typhoon and Salt Typhoon as examples.
The advisories Eclypsium says should move to the front of the queue include:
- SonicWall SMA1000: two actively exploited flaws, CVE-2026-15409 and CVE-2026-15410, used to install malware before SonicWall disclosed them and before they appeared in CISA’s Known Exploited Vulnerabilities catalog
- Fortinet FortiSandbox: advisories FG-IR-26-100 / FG-IR-26-141, covering CVE-2026-39808 and CVE-2026-25089, later added to CISA KEV on July 16
- Dell EMC Networking OS10 / SmartFabric Manager: DSA-2026-240 and DSA-2026-317, covering critical remotely exploitable, unauthenticated flaws
- F5 BIG-IP: advisory K000153397, addressing critical unauthenticated vulnerabilities in internet-facing ADCs and load balancers
- Juniper: advisories JSA110083 and JSA110086, with remotely exploitable flaws that can crash devices
- NVIDIA BlueField / ConnectX: Security Bulletin 5865, covering vulnerabilities in DPUs and SmartNICs used in AI and data-center infrastructure
Eclypsium also highlighted slower-moving firmware and hardware patch cycles. One example: HP’s Poly Video advisory arrived four months after an included Qualcomm GPU driver flaw, CVE-2026-21385, had already been exploited and added to CISA KEV.

Recommended reading
Apple patches Hide My Email flaw after a year
Unlike many roundups that count individual CVEs, InfraTrust tracks vendor advisories, since a single infrastructure advisory can bundle dozens or hundreds of vulnerabilities. That framing matters when a lower-scoring but internet-reachable bug may pose more risk than a higher-scoring flaw that requires local administrator access.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


