Exploited Edge Devices

The perimeter appliance is the most reliably weaponised class of software we track, and it is the one place in our graph where Chinese espionage groups and ransomware affiliates demonstrably reach for the same object.

Within CISA's Known Exploited Vulnerabilities catalog, the entries naming an edge or perimeter vendor carry the ransomware-association flag at more than twice the rate of KEV as a whole — 45.7% against 20.2%, measured 2026-08-06. Both figures are drawn from inside KEV, so whatever bias there is in how a vulnerability reaches that catalog applies equally to both sides of the comparison.

What no filter on this site can express is the grouping itself. "Perimeter appliance" is not a searchable string, not a vendor, and not a product; it is a judgement about where a device sits in a network. That judgement is what this page publishes, and everything beside it — severity, exploitation probability, which groups we tie to which flaw, what we have written about them — is read live from the same graph the rest of the site reads.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Peak weeks

The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Vulnerabilities

KEV marks a vulnerability CISA records as exploited in the wild.

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Recent activity

The most recent incidents in our log attributed to the groups above, from the last twelve months.

Our coverage

The 12 most recent of 35 briefings that mention a member of this collection.

How this list was chosen. Membership is hand-picked from KEV entries whose description names one of these products, plus the groups our graph ties to those entries by an actor-to-CVE link: Ivanti, Fortinet/FortiOS, Citrix/NetScaler, MOVEit, Cleo, Palo Alto/PAN-OS, SonicWall, Pulse Secure, Barracuda, GoAnywhere and ConnectWise ScreenConnect. The 45.7% figure above is that same match run over the KEV catalog on 2026-08-06 — stated with its method because a percentage whose selection rule is not published cannot be checked, and this one is circular by construction: it finds edge CVEs because it looks for edge vendor names. Read the vendor spread as a description of this list, not as a census of the exploited perimeter. We hold NO link between a victim organisation and a CVE (there is no incident-to-CVE table), so this page names no breach vector against any company. The ransomware groups here are listed because they exploit these flaws somewhere, not because any incident in our log is attributed to one of them.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions