The Perimeter Problem: What This Week’s CISA Alerts Tell CISOs About Edge Device Risk.
On September 9, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. Three of them sit on the same piece of infrastructure every enterprise depends on: the network edge.
A perfect CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center. An authentication bypass in Citrix NetScaler ADC and Gateway, already hit with dozens of exploitation attempts in the first weeks of September. A heap-based buffer overflow in Fortinet FortiOS that has already been used to infect close to 200 FortiGate devices with a piece of malware called PivotC2, in a campaign attributed to financially motivated actors. Federal agencies were given until September 12 to patch. Most private sector organizations do not have a hard deadline. That is exactly the problem.
This is not a one-week story
It is tempting to read this as three more CVEs to add to the patch queue. The data says otherwise. According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation now accounts for 31% of breaches as an initial access vector, up from 20% the year before, a 55% jump. That was enough to push vulnerability exploitation past credential abuse and phishing as the leading way attackers get in, for the first time in the report’s history. Edge devices and remote access infrastructure are a meaningful part of that shift: network devices specifically climbed from roughly 1.5% to 5% of breaches over the same period.
Research from VulnCheck adds a detail that should concern every CISO managing a distributed technology estate: 42.5% of exploited edge vulnerabilities in 2025 involved devices that were already end of life or approaching it, and 65% of botnet-driven exploitation specifically targeted unsupported products. Attackers are not hunting for zero days in cutting edge software. They are working through the list of devices your team has not gotten around to replacing.
Perhaps the most uncomfortable statistic in that research: only about 24% of actively exploited vulnerabilities in the dataset ever made it into CISA’s KEV catalog. If your vulnerability management program treats KEV as the finish line rather than the floor, there is a strong chance real exploitation activity is happening in your environment that no official list will ever flag for you.
Why the edge is such an attractive target
Firewalls, VPN concentrators, and management consoles exist to control access. That is precisely what makes them valuable once an attacker gets past them. A compromised laptop gets an attacker one user’s worth of access. A compromised firewall management interface, like the Cisco flaw disclosed this month, can hand an attacker root access and a foothold with visibility across the network it was supposed to protect.
Timelines have compressed at the same time. Proof of concept code for a newly disclosed edge vulnerability can circulate globally within hours. In some cases documented by VulnCheck, active exploitation was observed before a CVE number had even been assigned. A patch cycle built around monthly or quarterly maintenance windows is not built for that pace, no matter how disciplined the process looks on paper.
CISA has responded with a new binding operational directive requiring federal agencies to inventory their edge devices, report which ones are approaching end of support, and eliminate unsupported devices on a defined timeline over the next two years. The directive only binds federal civilian agencies, but CISA has been explicit that it wants private sector organizations, state and local governments, and international partners to adopt the same discipline voluntarily.
What this means for your program
A few practical takeaways for security leaders looking at this week’s news and the broader trend behind it:
Treat the perimeter as a living target, not an annual checkbox. If your external network penetration test happens once a year, you are validating a snapshot that may already be six months stale by the time an assessment report lands on your desk. Attackers are not waiting for your renewal cycle.
Build a real inventory of edge infrastructure, including support status. You cannot protect what you cannot see, and end of life devices are disproportionately represented in the exploitation data. This is a boring, unglamorous exercise, and it is also one of the highest leverage things a security team can do this quarter.
Pair scanning with adversarial testing. Vulnerability scanners are good at catching missing patches. They are considerably less reliable at catching authentication bypass logic flaws of the kind found in the Cisco and Citrix vulnerabilities disclosed this month, the sort of issue that often only surfaces when someone is actively trying to break the login flow the way an attacker would.
Assume patch cycles will lose the race sometimes, and plan for it. Segment management interfaces away from general network access. Limit who and what can reach administrative consoles. Build the assumption of eventual compromise into your architecture rather than betting everything on patching speed.
This is the gap between point in time assessments and continuous validation that we spend most of our time closing for clients. Orenda’s external and internal network penetration testing looks specifically for the authentication bypass and logic flaw classes of issues driving this year’s edge device breaches, and our continuous penetration testing and vulnerability management services are built around the reality that a once a year test cannot keep pace with exploitation timelines measured in days. If your last look at your perimeter was your last annual pentest, now is a reasonable time to ask how much has changed since.
The three vulnerabilities CISA flagged this week will get patched, eventually, by most organizations that are paying attention. The pattern behind them will not go away. The network edge is not a place to defend once a year and hope. It is the front door, and it deserves the same continuous attention as everything behind it.