Skip to content
Tech News
← Back to articles

New InfraTrust report reveals infrastructure flaws admins should patch first

read original more articles
Why This Matters

The InfraTrust report underscores the urgent need for organizations to prioritize patching vulnerabilities in critical infrastructure components, especially those actively exploited or exposed to remote threats. This focus is vital as state-sponsored actors increasingly target network edge devices, risking widespread disruption and data breaches. By emphasizing exploitability and exposure over traditional severity scores, the report guides more effective cybersecurity defenses in an evolving threat landscape.

Key Takeaways

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.

The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone.

The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.

The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.

The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.

In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.

What to patch first

The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.

Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.

... continue reading