New InfraTrust report reveals infrastructure flaws admins should patch first

Cybersecurity Experts Warn of Critical Infrastructure Flaws Exposing Organizations to Attackers

A new report from InfraTrust, a comprehensive knowledge base for infrastructure cybersecurity, has shed light on critical vulnerabilities affecting various infrastructure components. The inaugural July 2026 InfraTrust Pulse report highlights 61 advisories from major vendors, including six critical ones and 26 remotely exploitable, unauthenticated vulnerabilities.

These flaws are particularly concerning because they can be exploited by attackers to breach network edge devices, often used in critical infrastructure and telecommunications providers. In recent years, state-sponsored threat actors have repeatedly targeted vulnerable internet-facing infrastructure to gain unauthorized access to sensitive networks.

The report’s authors emphasize that traditional severity scores alone do not accurately reflect the risk posed by these vulnerabilities. They argue that organizations should prioritize patches based on exploitability, reachability, and exposure rather than relying solely on Common Vulnerability Scoring System (CVSS) scores. This approach helps administrators identify the most critical issues and address them first.

The report singles out several advisories as high-priority due to their potential for remote exploitation without authentication or active exploitation in the wild. These include:

* SonicWall SMA1000, where attackers were exploiting two actively exploited vulnerabilities (CVE-2026-15409 and CVE-2026-15410) before they were even disclosed by the vendor.

* Fortinet’s FortiSandbox, which contains two older critical command injection vulnerabilities (CVE-2026-39808 and CVE-2026-25089) that were recently added to CISA’s Known Exploited Vulnerabilities catalog due to active exploitation.

* Dell Networking’s EMC Networking OS10 and SmartFabric Manager, with critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management.

* F5 BIG-IP, which has unauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers.

These advisories were not published within the 30-day reporting period but are included in the report because organizations may still be vulnerable to attacks. Eclypsium emphasizes that these issues should be addressed urgently, as attackers often exploit known vulnerabilities before vendors can release patches or they are added to vulnerability catalogs.

In light of this report, it’s essential for administrators to review their infrastructure configuration and prioritize patches based on the risk posed by each vulnerability. This involves considering not only the severity score but also the potential impact of a breach and whether the vulnerability is actively being exploited in the wild. By taking proactive steps to address these high-priority vulnerabilities, organizations can significantly reduce their exposure to cyber threats.

Practical advice for readers: Review your organization’s infrastructure configuration and prioritize patches based on the risk posed by each vulnerability. This includes considering not only the severity score but also the potential impact of a breach and whether the vulnerability is actively being exploited in the wild. Regularly review vendor advisories, CISA’s Known Exploited Vulnerabilities catalog, and InfraTrust Pulse reports to stay informed about emerging threats and vulnerabilities affecting your infrastructure components.


Source: Bleeping Computer — 2026-07-22