Edge devices: a common entry point for APTs and common cybercriminals

Analytics2026-09-04, 08:45
Tenable and SentinelOne correlated two independent datasets: vulnerability telemetry from thousands of customer environments and the results of SentinelOne's cyber incident investigations. Together, the study covered 82 CVEs and 93 vulnerability–threat actor pairs and showed that both APT groups and financially motivated cybercriminals systematically exploit products from the same vendors.
The most telling result: at the individual CVE level, the two datasets overlapped by just 21%, while at the vendor level, the overlap was 79%. In other words, attackers may exploit different vulnerabilities, but they repeatedly return to the same product surfaces.
• F5 leads in terms of exposure: actively exploited CVEs were found in 53.8% of environments with its products. Next came Citrix (28.8%), Fortinet (24.9%), Ivanti (24.1%), and Check Point (18.6%). • Citrix vulnerabilities take the longest to remediate: the median was 461 days, and 71% of environments were still vulnerable after a year. • Ivanti vulnerabilities are exploited serially: for EPMM, a new actively exploited CVE emerged approximately every 8.5 months; for Connect Secure, every 13 months. • Fortinet leads in the diversity of attackers, despite its average exposure figures: its products were exploited by at least 29 distinct groups across five categories.
Although the overlap at the individual CVE level was smaller, the researchers still identified 12 edge device vulnerabilities with confirmed exploitation by multiple types of attackers — from groups linked to China, Russia, North Korea, and Iran to ransomware operators. Examples of the vulnerabilities are provided in the full article.
Paradoxically, the highest-priority vulnerabilities are remediated slower than the rest: the median remediation time was 146 days, compared with 122. The authors attribute this to the fact that updating critical edge devices often requires manual testing and additional approval procedures because of the risk of downtime.
The study shows that the key perimeter risk is tied less to individual high-profile CVEs than to attackers sustained interest in a limited set of critical products. Therefore, the priority should be not only to remediate the next vulnerability quickly, but also to reduce the external attack surface and limit opportunities for further attack progression after a device is compromised.
Vendors
Tenable
Sentinelone
F5
Citrix
Fortinet
Ivanti
More
Products
Connect Secure
Epmm