VYPR
advisoryPublished Jul 22, 2026· 1 source

Eclypsium Launches InfraTrust to Prioritize Critical Infrastructure Vulnerabilities

Eclypsium's new InfraTrust initiative and monthly report aim to help organizations prioritize patching of infrastructure, firmware, and edge device vulnerabilities based on real-world exploitability and exposure.

Eclypsium has introduced InfraTrust, a new knowledge base and monthly report designed to provide organizations with actionable intelligence on critical vulnerabilities affecting essential infrastructure. The initiative aims to shift the focus from solely relying on CVSS scores to a more pragmatic approach that considers exploitability, reachability, and real-world risk when prioritizing patches.

The inaugural July 2026 InfraTrust Pulse report highlights 61 infrastructure advisories from 14 vendors, identifying six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. This report underscores a growing trend where state-sponsored threat actors, particularly from Russia and China, are increasingly targeting vulnerable network edge devices and infrastructure components like routers, VPNs, and firewalls.

The InfraTrust report emphasizes prioritizing vulnerabilities that are actively exploited, internet-exposed, or remotely exploitable without authentication. Several specific advisories are called out for immediate attention. These include actively exploited vulnerabilities in SonicWall SMA1000 (CVE-2026-15409 and CVE-2026-15410), which were used to deploy custom malware before disclosure. Additionally, two critical command injection vulnerabilities in Fortinet FortiSandbox (CVE-2026-39808 and CVE-2026-25089), recently added to CISA's Known Exploited Vulnerabilities (KEV) catalog, are highlighted due to their active exploitation.

Other critical advisories flagged for prioritization include remotely exploitable, unauthenticated vulnerabilities in Dell Networking OS10 and SmartFabric Manager, which are noted for their large attack surfaces due to their Linux-based nature. F5 BIG-IP devices, often situated at network perimeters, are also a focus due to unauthenticated, network-reachable flaws. Juniper Networks advisories highlight remotely exploitable flaws that can lead to denial-of-service conditions, while NVIDIA's BlueField DPUs and ConnectX SmartNICs, crucial for AI and data-center infrastructure, also have noted vulnerabilities.

Eclypsium also points out the significant lag often seen in firmware and hardware updates. For instance, an HP Poly Video advisory was released four months after a Qualcomm GPU driver vulnerability (CVE-2026-21385) within it was already being exploited and added to the KEV catalog. This highlights the challenge of securing the entire supply chain, from core components to integrated hardware.

Unlike typical vulnerability roundups that list individual CVEs, InfraTrust focuses on vendor advisories, recognizing that a single advisory can encompass dozens or even hundreds of vulnerabilities. This approach provides a more holistic view of an organization's infrastructure risk. The report's methodology aims to equip security teams with the intelligence needed to proactively defend against sophisticated attacks targeting critical infrastructure.

The initiative comes at a critical time, as organizations grapple with increasingly sophisticated threat actors and the complexity of securing modern IT environments. By providing a more nuanced prioritization framework, InfraTrust seeks to empower administrators to allocate resources effectively and mitigate the most pressing risks to their operational continuity and data security.

Synthesized by Vypr AI