HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Eclypsium InfraTrust Pulse Highlights 26 Remotely‑Exploitable Infrastructure Vulnerabilities, Including Actively‑Exploited Flaws in SonicWall, Fortinet, Dell, and F5

Eclypsium’s July 2026 InfraTrust Pulse aggregates 61 advisories and flags 26 remotely‑exploitable, unauthenticated flaws—six critical and several in CISA’s KEV catalog. The findings underscore the need for SOC 2‑aligned vulnerability prioritization and continuous audit evidence.

LiveThreat™ Intelligence · 📅 July 23, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Eclypsium InfraTrust Pulse Highlights 26 Remotely‑Exploitable Infrastructure Vulnerabilities, Including Actively‑Exploited Flaws in SonicWall, Fortinet, Dell, and F5

What Happened — Eclypsium’s new InfraTrust knowledge base released its inaugural July 2026 Pulse report, aggregating 61 advisories from 14 infrastructure vendors. The report flags 26 remotely‑exploitable, unauthenticated vulnerabilities (six rated critical) and surfaces several flaws already listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Why It Matters for Compliance & Audit Readiness

  • The highlighted flaws map directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) controls; failing to remediate them leaves a gap in documented change‑control evidence.
  • Continuous‑compliance programs must ingest external vulnerability feeds, prioritize remediation, and retain proof‑of‑remediation to satisfy audit‑ready evidence requirements.
  • Verisq’s Control Mapping capability can automatically correlate each advisory to the relevant SOC 2 control, generating real‑time audit evidence.

Who Is Affected — Enterprises that operate internet‑exposed routers, firewalls, VPN appliances, load balancers, and data‑center networking gear; sectors include telecom, cloud providers, and any organization with edge devices.

Recommended Actions

  • Map each listed advisory to your SOC 2 control set (e.g., CC6.1, CC7.1) and record remediation tickets as audit evidence.
  • Integrate a threat‑intelligence feed (e.g., InfraTrust Pulse) into your vulnerability‑management platform for continuous prioritization.
  • Validate that patching windows, change‑approval workflows, and post‑remediation testing are documented and retained for audit review.

Source: BleepingComputer – New InfraTrust report reveals infrastructure flaws admins should patch first

Technical Notes

  • Advisories span SonicWall SMA1000 (remote‑access appliance), Fortinet FortiSandbox (unauthenticated command injection), Dell Networking OS10/SmartFabric Manager (fabric‑management RCE), F5 BIG‑IP (application delivery controller), Juniper (DoS‑capable flaws), and NVIDIA BlueField/ConnectX (DPUs/SmartNICs).
  • Many are flagged in CISA’s KEV catalog, indicating active exploitation in the wild.
📰 Original Source
https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →