An intruder walked out of a FortiGate firewall carrying the device's configuration file. Inside it were the LDAP bind credentials for a directory service account. A few hours later two new computers appeared in the victim's Active Directory, neither of them carrying a Service Principal Name, which is unusual for a legitimate domain join, and the attribute that records who created an account pointed straight back at the stolen one.
The firewall was the whole intrusion. Everything after it was the attacker spending access the organization had already granted.
That case is one thread in a joint study published on 26 August by Tenable's Research Special Operations team and SentinelOne's Incident Readiness and Response practice. The two firms pooled datasets that were never built to be compared, and the resulting analysis lands on an uncomfortable finding. State intelligence services and ransomware crews are not working different parts of the internet. On edge devices they are queuing at the same doors.
Two datasets that never met
Tenable contributed exposure telemetry from its Tenable One platform, covering thousands of customer environments and measuring what edge gear is deployed, what is vulnerable, and how long it stays that way. SentinelOne contributed twelve months of digital forensics and incident response casework, which records not what could be exploited but what was, in rooms where somebody had already called for help. Combined, the two sets name 82 distinct vulnerabilities, and only 17 appear in both. At the level of the individual bug the overlap is 21%. The two teams were, mostly, not looking at the same flaws.
Then the picture inverts. Eleven of the 14 vendors in Tenable's focal set turn up in SentinelOne's casework, a 79% convergence. Narrow the comparison to edge and remote-access kit and the agreement is total. Tenable independently identified seven edge vendors, Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper and VMware, and all seven appear in SentinelOne's cases. Different vulnerabilities, same vendors. Apache and SAP were the notable absentees from the incident response side, and a single Progress case was closed as a false positive.
That distinction carries the whole exercise. Had both sets landed on the same individual CVEs, the advice would be simple: patch these ten things and the problem shrinks. What the data shows instead is that unrelated attackers keep arriving at the same small group of products and then finding their own separate ways in. Patching this quarter's Ivanti bug does not take Ivanti off anybody's list.
Spies and extortionists, one entry point
Twelve vulnerabilities in the combined corpus carry confirmed multi-nexus attribution, meaning state-sponsored and criminal operators have each been documented exploiting the same flaw independently, across five categories: China, Russia, North Korea, Iran and ransomware. Four illustrate the pattern. CVE-2026-15409 in SonicWall's SMA1000 appliances was worked by an unattributed group tracked as UTA0533 and then by the INC Ransomware operation, an espionage to extortion succession on an active zero-day. CVE-2023-42793 in JetBrains TeamCity drew Russia's APT29 and North Korea's Lazarus Group, two state services on one bug. CVE-2024-3400 in Palo Alto's GlobalProtect began as a China-nexus zero-day and was later reused by ransomware operators. CVE-2024-24919 in Check Point's Quantum gateways was hit by the China-nexus PurpleHaze cluster and by Iran's Fox Kitten. The remaining eight span Fortinet, Citrix, Cisco and Ivanti product lines.
The attribution behind those pairs is graded rather than asserted. The study scores all 93 of its vulnerability to actor pairs, covering roughly 39 named actors, into DIRECT, TECHNIQUE-ALIGNED or INFERRED tiers using a five-part rubric that weighs how direct the attribution is, where the evidence came from, how recent it is, what role the exploit played, and whether anyone else corroborated it.
Actor density tracks vendor exposure. Fortinet products face 29 distinct threat actors spanning all five categories, Citrix 22 across five, Ivanti 19 across four, Palo Alto Networks nine across three, and Check Point six across two. Not one of the focal vendors is somebody else's problem.
CISA gave three days. The median is 146.
We checked the four showcase vulnerabilities against CISA's own Known Exploited Vulnerabilities catalog, in the version published on 25 August 2026. All four are listed, and CISA flags every one of them as known to have been used in ransomware campaigns, which is a third and independent line of support for the convergence the two firms describe. The SonicWall zero-day is the sharpest entry in the set. CISA added CVE-2026-15409 on 14 July 2026 and set the federal remediation deadline at 17 July, three days later.
Set that against what the study measured. Across Tenable's 238-CVE high-priority list, high-priority vulnerabilities carry a median remediation time of 146 days, against 122 days for everything else, a 24-day gap the researchers report as statistically significant. The bugs everybody agrees are most urgent are the ones that wait longest.
The reason is structural rather than negligent. Edge devices sit at the boundary, so patching a VPN gateway or a firewall means downtime for every user behind it, and change management gates multiply. They rarely run endpoint agents, they often need firmware updates with manual validation, and they frequently sit outside an active support contract. The 2026 Verizon Data Breach Investigations Report, cited in the study, found median patch time rising from 32 to 43 days year over year even as exploitation overtook credential theft as the leading initial access vector.
Fortinet's headlines outrun its exposure
The exposure picture is flatter than two years of coverage would suggest. Measured as the share of monitored customer environments carrying at least one exposed, actively exploited vulnerability, Check Point sits at 18.6%, Ivanti at 24.1%, Fortinet at 24.9% and Citrix at 28.8%, a ten-point band. Fortinet, the vendor most associated in the press with edge-device attacks, is mid-pack.
Two vendors outside that group matter more. F5 is the most broadly exposed of the statistically robust samples, with 53.8% of 2,784 monitored environments running F5 products carrying at least one actively exploited flaw. Citrix is the slowest to recover, at a median 461 days to patch, with 71% of affected environments still carrying unpatched Citrix vulnerabilities a full year on. Juniper, VMware, Palo Alto Networks and Cisco all show exposure rates above 50%, but each rests on fewer than 50 in-sample environments, so read those as direction rather than measurement.
Ivanti supplies the timing. Ivanti Endpoint Manager Mobile has produced a newly exploited vulnerability roughly every 8.5 months, and Ivanti Connect Secure roughly every 13. We covered the most recent round of Ivanti patches earlier this month. On that cadence the next one is a scheduling question rather than a probability.
What this does and does not prove
Both datasets are shaped by how they were collected, and the study says so. Tenable's exposure figures are container-grain, counting the share of organizations with at least one vulnerable asset rather than raw asset counts, so 24.9% does not mean a quarter of all Fortinet boxes are unpatched. SentinelOne's casework reflects who picked up the phone, not install base. The thin-sample vendors above are directional signals, not league positions. And the edge-appliance subset of the remediation analysis, 52 vulnerabilities, showed an 8-day gap in the same direction as the headline finding without reaching statistical significance. What the work establishes solidly is the vendor-level convergence and the multi-nexus attribution. The exact exposure percentages are narrower claims than they look.
Patch F5 and Citrix first
The authors put F5 and Citrix at the front of the queue, because those two combine the highest exposure with the slowest remediation across the reliable samples. Audit Ivanti Connect Secure and EPMM deployments now, and budget patching capacity on the assumption that a new actively exploited flaw lands within the year. Write patch service level agreements specific to edge devices, shorter than the organizational default, because general priority frameworks demonstrably do not translate into faster patching at the boundary. Cut the enabled feature set on these appliances to shrink what is reachable, and run endpoints in protect mode so an attacker who does get through the gateway cannot move sideways unopposed. And treat attribution, severity and exposure volume as three separate signals: a program that prioritizes on CVSS alone will systematically underrate flaws with strong exploitation evidence and modest scores.
The uncomfortable part is not that any single appliance is weak. It is that the list of appliances worth attacking is short, well known to everyone who wants in, and stable enough that two teams working from completely different evidence wrote down the same seven names.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.