Network & Infrastructure

42.5% of Exploited Edge Flaws Hit Devices Past Their Support Life, and Patch Deadlines Now Run in Days

VulnCheck found that nearly half of the edge vulnerabilities attackers exploited last year sat on hardware its vendor had stopped fixing. This month CISA gave agencies two days, then three, to patch the firewalls and gateways that are still supported.

September 28, 2026 · Network & Infrastructure
Close-up of a network rack with rows of media converter modules, blue ethernet cables plugged in along the top and yellow fiber patch cords along the bottom, green and amber status lights glowing

Key Takeaways

  • VulnCheck found 42.5% of the edge device vulnerabilities exploited in 2025 affected end-of-life or likely end-of-life hardware, and 65% of the flaws botnets exploited targeted unsupported devices.
  • Verizon's 2026 Data Breach Investigations Report found 31% of breaches now start with a software vulnerability, overtaking stolen passwords as the most common way in.
  • On September 10, CISA added exploited Cisco, Citrix, and Fortinet edge flaws to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 12 to patch them.
  • CISA's Binding Operational Directive 26-02 requires federal agencies to remove every identified end-of-support edge device by August 5, 2027, and the FBI and UK NCSC urge all organizations to follow suit.

The firewall, the VPN gateway, and the router at the edge of the network were built to be the part of the estate attackers could not get past. They have become the part attackers go to first. Verizon's 2026 Data Breach Investigations Report found that 31% of breaches now start with a software vulnerability, beating stolen passwords as the most common way in. And the vulnerabilities that matter most are increasingly sitting on hardware nobody is patching any more, because nobody can: the vendor stopped shipping fixes years ago.

Nearly Half the Exploited Edge Flaws Had No Fix Coming

VulnCheck's 2026 State of Exploitation report on network edge devices tracked the edge vulnerabilities attackers actually used in 2025. Of those, 42.5% affected devices that were end-of-life or likely end-of-life. Among the flaws exploited by botnets, the share was higher still: 65% targeted unsupported devices. Consumer routers and globally distributed networking products accounted for 56% of the exploited edge vulnerabilities.

That matters for enterprise teams because the definition of "the edge" has quietly widened. A branch office router, a remote worker's home gateway, a load balancer that outlived its support contract: each one is an internet-facing device that terminates connections the organization trusts. VulnCheck also found that exploitation frequently runs ahead of disclosure. It issued CVEs for 18 vulnerabilities only after its honeypots and canary systems had already caught attackers using them, and only 23.7% of the vulnerabilities it identified appeared in CISA's Known Exploited Vulnerabilities catalog. A patch program that waits for the catalog to move is, by design, working from a partial list.

The federal government has stopped treating this as a patching problem at all. CISA's Binding Operational Directive 26-02, issued February 5, requires civilian agencies to inventory end-of-support edge devices, decommission those on CISA's list within 12 months, remove every identified device within 18 months, and have a continuous discovery process running within 24. The directive's rationale is blunt: recent campaigns show attackers using these devices "as a means to pivot" into agency networks, and edge devices are especially attractive because they integrate with identity management systems. The directive binds only federal agencies, but CISA, the FBI, and the UK's National Cyber Security Centre have all encouraged every organization to follow the same guidance.

The Supported Devices Are Not Buying Much Time Either

Replacing unsupported hardware closes one door. It does not slow the attacks on current equipment. On September 10, CISA added three actively exploited edge flaws to its catalog and gave federal agencies until September 12 to patch them. The list read like a cross-section of the modern perimeter: an authentication bypass rated 10.0 in Cisco Secure Firewall Management Center, exploited since August; an authentication bypass rated 9.3 in Citrix NetScaler ADC and Gateway, with 56 exploitation attempts observed from September 3, including 36 on September 8 alone; and a Fortinet heap overflow tied to a campaign that targeted more than 3,000 IP addresses and infected 178 devices with a remote access trojan.

A week later the window tightened again. CISA added an authentication bypass in Cisco Identity Services Engine, also rated 10.0, to the catalog on September 17 and, according to Cybersecurity Market's analysis, gave agencies three days to patch against a standard window of three weeks. No configuration workaround exists; an attacker who can reach the management interface gains root access with no credentials and no user interaction. In August, a separate zero-day in the Remote Access SSL VPN service of Cisco's ASA and Firepower Threat Defense software was already being used to force exposed appliances to reload, dropping VPN sessions and any traffic that depended on the firewall staying up.

None of this is a single-vendor story. Three vendors shared one CISA update, a fourth product line followed a week later, and the pattern across them is identical: internet-facing management and VPN services, authentication bypasses, and deadlines measured in days rather than maintenance windows. SentinelOne's analysis of edge intrusions describes compromised edge devices being used for credential interception, web shell deployment, and account creation before attackers move deeper into the network. Its conclusion is hard to argue with: "The perimeter isn't failing, it's already failed."

Why the Maintenance Window Model Breaks at the Edge

Most enterprises still patch network infrastructure on a quarterly or monthly change calendar, because rebooting a firewall or VPN concentrator interrupts the business. That cadence was designed for a world where exploitation followed disclosure by weeks. It now follows by days, and sometimes, as VulnCheck's honeypot data shows, it arrives before a CVE exists at all. Meanwhile the unsupported devices that make up nearly half the exploited population will never receive a patch to schedule. The practical response is to shrink what the edge exposes, know exactly which devices sit there, and assume any one of them may already be compromised.

The edge used to be the part of the network security teams worried about least, because it was the part vendors hardened most. That assumption no longer holds. When nearly half the exploited flaws sit on devices that will never be fixed, and the rest arrive with deadlines of two or three days, the organizations that stay out of next year's breach report will be the ones that treat every internet-facing appliance as a lifecycle decision, not a set-and-forget box.

Share

More in Network & Infrastructure

All Resources →