New InfraTrust report reveals infrastructure flaws admins should patch first
A new InfraTrust report highlights infrastructure flaws that administrators should prioritize patching first. The report aggregates security advisories from major infrastructure vendors and highlights vulnerabilities that should be prioritized based on exploitability, exp…
Intelligence analysis by Llama

The InfraTrust report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.
Imagine you have a big house with many doors and windows. Each door and window is like a vulnerability in your computer's infrastructure. Some of these doors and windows are easy to open, while others are harder. The InfraTrust report helps you find the easy-to-open doors and windows and patch them first to keep your house (or computer) safe.
Analysis
A New Approach to Prioritizing Vulnerabilities
The InfraTrust report marks a new approach to prioritizing vulnerabilities in infrastructure. Rather than relying solely on CVSS scores, the report aggregates security advisories from major infrastructure vendors and highlights vulnerabilities that should be prioritized based on exploitability, exposure, and real-world risk. This approach is especially important given the increasing number of attacks on vulnerable network edge devices.
The Focus on Infrastructure Security
The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices. In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.
What to Patch First
The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. These advisories include SonicWall SMA1000, Fortinet FortiSandbox, Dell Networking, F5 BIG-IP, Juniper Networks, and NVIDIA. Each of these advisories contains critical vulnerabilities that can be exploited remotely without authentication, making them a priority for administrators to patch first.
The Importance of Firmware and Hardware Updates
The report also highlights the importance of firmware and hardware updates. Updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them. As an example, HP's Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
Key points
- The InfraTrust report highlights infrastructure flaws that administrators should prioritize patching first.
- The report aggregates security advisories from major infrastructure vendors and highlights vulnerabilities that should be prioritized based on exploitability, exposure, and real-world risk.
- The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.
- The report emphasizes the importance of firmware and hardware updates in reducing the risk of attacks on infrastructure.
If administrators prioritize patching these vulnerabilities, they can reduce the risk of attacks on their infrastructure. This can lead to a safer and more secure online environment for everyone.
If administrators do not prioritize patching these vulnerabilities, they may leave their infrastructure open to attacks. This can lead to data breaches, system crashes, and other security issues.



