Critical Infrastructure Flaws Expose Organizations to Remote Attacks
A newly released report from InfraTrust, a cybersecurity knowledge base and monthly reporting service, has shed light on 61 infrastructure advisories from major vendors, including six critical ones. The report, compiled by Eclypsium’s Principal Security Researcher Paul Asadoorian, highlights vulnerabilities that administrators should prioritize based on exploitability, exposure, and real-world risk rather than severity scores alone.
The focus of the report comes at a time when state-sponsored threat actors from Russia and China have been increasingly targeting vulnerable network edge devices. In recent years, attackers have exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers. These attacks often go unnoticed until significant damage has been done.
InfraTrust’s report specifically targets six advisories that require immediate attention from administrators due to their high risk of exploitation and potential impact on organizations. The affected vendors include SonicWall, Fortinet, Dell Networking, F5 BIG-IP, Juniper, and NVIDIA BlueField/ConnectX. These vulnerabilities can be remotely exploited without authentication, allowing attackers to gain control of internet-exposed infrastructure.
One notable example is the recent exploitation of two actively exploited vulnerabilities in SonicWall’s SMA1000 remote-access appliance (CVE-2026-15409 and CVE-2026-15410). Attackers were able to install custom malware weeks before SonicWall disclosed the flaws, highlighting the need for prompt action by administrators. Similarly, Fortinet’s FortiSandbox advisories contain two older critical command injection vulnerabilities that were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 16.
Dell Networking’s EMC Networking OS10 and SmartFabric Manager also have critical vulnerabilities in the report. The OS10 advisory alone includes hundreds of upstream fixes, illustrating the large attack surface of network operating systems. F5 BIG-IP’s unauthenticated vulnerabilities affecting internet-exposed application delivery controllers and load balancers are another area of concern.
The InfraTrust report emphasizes that organizations should prioritize patching based on exploitability, reachability, and exposure rather than relying solely on Common Vulnerability Scoring System (CVSS) scores. This approach ensures that the most critical and high-risk vulnerabilities receive prompt attention from administrators.
For readers who manage network infrastructure, it is crucial to review the advisories listed in InfraTrust’s report and prioritize patching based on the risk factors mentioned above. Regularly updating firmware and software can significantly reduce the likelihood of exploitation by attackers.
Source: Bleeping Computer — 2026-07-22