VulnCheck found that nearly half of the edge vulnerabilities attackers exploited last year sat on hardware its vendor had stopped fixing. This month CISA gave agencies two days, then three, to patch the firewalls and gateways that are still supported.
Key Takeaways
The firewall, the VPN gateway, and the router at the edge of the network were built to be the part of the estate attackers could not get past. They have become the part attackers go to first. Verizon's 2026 Data Breach Investigations Report found that 31% of breaches now start with a software vulnerability, beating stolen passwords as the most common way in. And the vulnerabilities that matter most are increasingly sitting on hardware nobody is patching any more, because nobody can: the vendor stopped shipping fixes years ago.
VulnCheck's 2026 State of Exploitation report on network edge devices tracked the edge vulnerabilities attackers actually used in 2025. Of those, 42.5% affected devices that were end-of-life or likely end-of-life. Among the flaws exploited by botnets, the share was higher still: 65% targeted unsupported devices. Consumer routers and globally distributed networking products accounted for 56% of the exploited edge vulnerabilities.
That matters for enterprise teams because the definition of "the edge" has quietly widened. A branch office router, a remote worker's home gateway, a load balancer that outlived its support contract: each one is an internet-facing device that terminates connections the organization trusts. VulnCheck also found that exploitation frequently runs ahead of disclosure. It issued CVEs for 18 vulnerabilities only after its honeypots and canary systems had already caught attackers using them, and only 23.7% of the vulnerabilities it identified appeared in CISA's Known Exploited Vulnerabilities catalog. A patch program that waits for the catalog to move is, by design, working from a partial list.
The federal government has stopped treating this as a patching problem at all. CISA's Binding Operational Directive 26-02, issued February 5, requires civilian agencies to inventory end-of-support edge devices, decommission those on CISA's list within 12 months, remove every identified device within 18 months, and have a continuous discovery process running within 24. The directive's rationale is blunt: recent campaigns show attackers using these devices "as a means to pivot" into agency networks, and edge devices are especially attractive because they integrate with identity management systems. The directive binds only federal agencies, but CISA, the FBI, and the UK's National Cyber Security Centre have all encouraged every organization to follow the same guidance.
Replacing unsupported hardware closes one door. It does not slow the attacks on current equipment. On September 10, CISA added three actively exploited edge flaws to its catalog and gave federal agencies until September 12 to patch them. The list read like a cross-section of the modern perimeter: an authentication bypass rated 10.0 in Cisco Secure Firewall Management Center, exploited since August; an authentication bypass rated 9.3 in Citrix NetScaler ADC and Gateway, with 56 exploitation attempts observed from September 3, including 36 on September 8 alone; and a Fortinet heap overflow tied to a campaign that targeted more than 3,000 IP addresses and infected 178 devices with a remote access trojan.
A week later the window tightened again. CISA added an authentication bypass in Cisco Identity Services Engine, also rated 10.0, to the catalog on September 17 and, according to Cybersecurity Market's analysis, gave agencies three days to patch against a standard window of three weeks. No configuration workaround exists; an attacker who can reach the management interface gains root access with no credentials and no user interaction. In August, a separate zero-day in the Remote Access SSL VPN service of Cisco's ASA and Firepower Threat Defense software was already being used to force exposed appliances to reload, dropping VPN sessions and any traffic that depended on the firewall staying up.
None of this is a single-vendor story. Three vendors shared one CISA update, a fourth product line followed a week later, and the pattern across them is identical: internet-facing management and VPN services, authentication bypasses, and deadlines measured in days rather than maintenance windows. SentinelOne's analysis of edge intrusions describes compromised edge devices being used for credential interception, web shell deployment, and account creation before attackers move deeper into the network. Its conclusion is hard to argue with: "The perimeter isn't failing, it's already failed."
Most enterprises still patch network infrastructure on a quarterly or monthly change calendar, because rebooting a firewall or VPN concentrator interrupts the business. That cadence was designed for a world where exploitation followed disclosure by weeks. It now follows by days, and sometimes, as VulnCheck's honeypot data shows, it arrives before a CVE exists at all. Meanwhile the unsupported devices that make up nearly half the exploited population will never receive a patch to schedule. The practical response is to shrink what the edge exposes, know exactly which devices sit there, and assume any one of them may already be compromised.
The edge used to be the part of the network security teams worried about least, because it was the part vendors hardened most. That assumption no longer holds. When nearly half the exploited flaws sit on devices that will never be fixed, and the rest arrive with deadlines of two or three days, the organizations that stay out of next year's breach report will be the ones that treat every internet-facing appliance as a lifecycle decision, not a set-and-forget box.
Guide
Retiring end-of-support edge devices under a BOD 26-02 style timeline is a chance to consolidate firewall policy rather than replace boxes one for one. This guide covers unifying that policy across on-premises, cloud, and distributed edge.
Download
Guide
VPN gateways and management interfaces sat at the center of this month's exploited flaws. This guide covers VPN architecture, zero-trust network access, and the continuous monitoring that catches a compromised remote access path early.
Download
Guide
If a firewall can be bypassed with no credentials, access behind it cannot depend on having passed through it. This roadmap breaks zero trust into sequenced projects so an assume-breach edge becomes a delivery plan, not a slogan.
Download
The share naming infrastructure as their primary AI constraint has more than quadrupled in two years.
Edge deployments have moved from pilot to production across manufacturing, retail and healthcare.
Analysis of 300 enterprise workloads finds the true cost gap is far narrower than most TCO models suggest.