August 26, 2026
The second InfraTrust Pulse highlights that this month's attacks landed on the management plane, with particular focus on firewalls, and that patching alone did not close them. From July 18 through August 24, we tracked 118 new security advisories across 12 vendors, covering 1,051 distinct CVEs. 18 had critical CVSS scores, but 40 are remotely exploitable with no authentication, and that is still the figure that should drive remediation. Another 74 advisories were revised without being republished, so 39% of the month's activity is invisible to any process that keys on publish date. Your top priority is Cisco Secure Firewall, which took two KEV additions in two weeks: the FMC static credential (CVE-2026-20316, CVSS 5.3, KEV July 29) and the ASA/FTD SSL VPN denial of service (CVE-2026-20349, CVSS 8.6, KEV August 11). Then apply the hotfix for the FMC authentication bypass (CVE-2026-20079, CVSS 10.0), revised August 5 with new compromise-detection guidance. Next, patch Arista's VeloCloud Orchestrator (ARISTA0144, CVE-2026-16812, CVSS 10.0), actively exploited in customer networks, and Fortinet's FortiOS...