eCommerceNews US - Technology news for digital commerce decision-makers
United States
Eclypsium flags 1,051 CVEs in infrastructure advisories

Eclypsium flags 1,051 CVEs in infrastructure advisories

Fri, 28th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Eclypsium has published its August InfraTrust Pulse report on infrastructure security advisories, identifying 118 new advisories covering 1,051 CVEs.

The monthly analysis found that 40 of those vulnerabilities can be exploited remotely without authentication, while 74 previously issued advisories were revised during the reporting window. The findings highlight growing concern over the management systems used to administer fleets of firewalls, routers and switches.

Management focus

Paul Asadoorian, the researcher leading the report, said attacks during the period were concentrated on the management plane rather than the network devices themselves. The report highlighted exploited flaws affecting Cisco Secure Firewall Management Centre, Arista VeloCloud Orchestrator, HPE Aruba SD-WAN Orchestrator and Check Point SmartConsole.

Those products sit above the underlying devices and control policy, configuration and administration across multiple systems. A breach at that layer can give an attacker a route into an entire estate while resembling routine administrative activity.

Among the Cisco issues singled out was CVE-2026-20316, a medium-severity flaw in Secure Firewall Management Centre that allows an unauthenticated remote attacker to log in with hardcoded low-privilege credentials. The issue was added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue and could be chained with other flaws to escalate privileges.

The report also pointed to CVE-2026-20079, a separate authentication bypass in the same product line with a CVSS score of 10.0. Although the vulnerability was published earlier, the advisory was revised during the period with updated hotfix guidance and more detailed instructions for detecting signs of compromise.

Another Cisco issue, CVE-2026-20349, affects ASA and FTD remote access SSL VPN services and can be triggered through a crafted HTTP request that forces a device reload. It too was added to the exploited vulnerabilities catalogue on the day it was published.

CVSS limits

A central argument in the report is that CVSS severity scores can mislead defenders when used in isolation. Of the vendor advisories added to the exploited vulnerabilities catalogue during the period, three were rated medium, six high and two critical, showing that actively exploited flaws do not always carry the highest numerical scores.

The report contrasted that with the 18 advisories rated critical during the month and the 40 vulnerabilities that were both remotely exploitable and required no authentication. It argued that those groups do not fully overlap, making context and evidence of exploitation more important than score alone.

Fortinet's CVE-2025-68686 was cited as an example. Rated 5.9, the vulnerability allows attackers who had already compromised a FortiGate device through earlier bugs to preserve access despite patching by bypassing a symlink persistence fix with a modified path.

The report said the case shows why patching alone may not be enough after an intrusion. Organisations may update software versions while leaving attacker-created persistence in place unless they also check for indicators of compromise and rotate credentials.

Broader trends

Beyond firewall and SD-WAN management products, the analysis tracked large roll-up advisories from Dell, revised firmware notices from Lenovo and HP, and a cluster of security bulletins affecting Nvidia software and hardware used in AI infrastructure. Risks are emerging across the stack, from inference-serving software and telemetry tools to networking components, management controllers and TPM reference code.

The report also drew attention to the operational burden created by revised advisories. Of the 191 advisories either added or updated during the period, 39% were revisions rather than newly published notices.

That matters because revisions can introduce new affected models, updated fixed versions, corrected severity ratings or fresh guidance on detecting earlier compromise. Cisco's revised guidance for Secure Firewall Management Centre was presented as one of the most important documents for operators during the month, even though the underlying vulnerability was not new.

Eclypsium's analysis also referred to external research on internet-exposed baseboard management controllers, or BMCs. It cited separate scans that found tens of thousands of BMC services exposed online, with one dataset indicating that more than half of the exposed systems belonged to Supermicro and another showing that 54% of externally visible BMCs had at least one critical vulnerability.

Supply-chain concerns also featured. The report noted research from VulnCheck on router models from Shenzhen Zhibotong Electronics sold under the Zbtlink, ZBT and Wiflyer brands, which were found to ship with an implant based on a command-and-control project first published in 2015.

The August edition is the second monthly release in the InfraTrust Pulse series. It covers advisories issued across 12 vendors and treats updates to older notices as a core part of the exposure picture rather than background maintenance.

"If your vulnerability process keys on publish date, it saw none of this. A revised advisory can mean a new affected model, a new fixed version, a corrected severity, or, as with the Cisco FMC bypass, new instructions for finding out whether you were already compromised. Tracking the last modified date is equally as important as tracking the published date," said Asadoorian.