Skip to content
Cyber Defense Technologies

Threat Intelligence

Edge Devices Under Attack: VPNs, Firewalls and Gateways

The devices that guard the perimeter have become a favorite target. Why VPNs, firewalls, routers and gateways are exploited so often, what recent advisories describe, and how to defend devices you often cannot inspect.

By Cyber Defense Technologies January 6, 2026 4 min read

Perimeter devices, such as VPN concentrators, firewalls, routers, load balancers and secure gateways, sit between an organization and the internet. They are designed to keep attackers out. Increasingly, they are how attackers get in.

Over the past several years, government agencies and security researchers have documented a steady stream of critical vulnerabilities in edge devices from many vendors, and rapid exploitation of those vulnerabilities by criminal and state-sponsored actors alike.

Why edge devices are attractive targets

  • They are exposed by design. Edge devices must be reachable from the internet to do their jobs.
  • They are trusted. A compromised VPN or firewall sits at a privileged point, with access to internal networks and the traffic passing through.
  • They are hard to monitor. Most cannot run endpoint detection tools, and their logs are often not collected centrally.
  • They are hard to inspect. Organizations frequently cannot examine the underlying operating system for signs of compromise.
  • They are patched slowly. Updates may require maintenance windows and can break connectivity, so they are sometimes delayed.
  • They live a long time. Devices often remain in service past the end of vendor support.

What advisories describe

Several patterns recur in public reporting:

  • Rapid exploitation after disclosure. Critical edge device vulnerabilities often appear in CISA's Known Exploited Vulnerabilities catalog soon after disclosure, and CISA has issued emergency directives requiring federal agencies to act quickly on specific edge device flaws, such as Emergency Directive 24-01 for Ivanti Connect Secure and Policy Secure gateways in January 2024.
  • Persistence that survives patching. In some cases, attackers modified devices so their access persisted even after updates, making integrity checks and, sometimes, factory resets or replacement necessary.
  • State-sponsored campaigns. An August 2025 joint advisory from agencies in 13 countries described state-sponsored actors, publicly tracked as Salt Typhoon, exploiting known vulnerabilities in routers and other network edge devices to compromise telecommunications providers and other organizations worldwide, modifying router configurations to maintain access.
  • Use of end-of-life devices. Unsupported routers and firewalls have been compromised and used to build networks for hiding attacker traffic.

Edge device defense checklist

  • Inventory every VPN, firewall, router and gateway
  • Patch known exploited vulnerabilities urgently
  • Remove management interfaces from the internet
  • Require phishing-resistant MFA for administration
  • Send device logs to central monitoring
  • Check integrity and configuration for unauthorized changes
  • Replace devices that are past end of support
  • Plan to hunt for compromise when a critical flaw is disclosed

Defending the edge

Know what you have

Maintain an inventory of every internet-facing device, including model, firmware version, support status and owner. Many organizations discover forgotten devices only after they are compromised.

Patch like it matters

Treat critical vulnerabilities in edge devices, especially those listed as known exploited, as emergencies. Plan maintenance processes so urgent updates can be applied quickly. Subscribe to vendor and CISA notifications.

Remove management interfaces from the internet

Administrative interfaces should be reachable only from trusted internal management networks, not from the internet.

Strengthen administrative access

Require phishing-resistant multifactor authentication for device administration, use dedicated administrative accounts, and remove default and unused accounts.

Collect and review device logs

Send edge device logs to a central platform and alert on configuration changes, new accounts, unusual administrative logons and unexpected connections.

Check integrity

Use vendor-provided integrity checking tools where available, compare running configurations with approved baselines, and follow vendor and CISA guidance on hunting for compromise after major vulnerabilities are disclosed.

Replace what is no longer supported

Unsupported devices will not receive fixes. Budget for replacement before end of support.

Assume compromise is possible

Segment the network so a compromised edge device does not provide unrestricted internal access, and monitor internal traffic from edge devices for unusual behavior.

Frequently asked questions

If we patched quickly, are we safe? Not necessarily. If a device was compromised before patching, attackers may retain access. After critical disclosures, follow guidance on checking for compromise, not only on patching.

Should we move away from traditional VPNs? Many organizations are adopting approaches that reduce exposed services, such as zero trust access architectures. Any replacement still needs careful configuration and monitoring.

How do we test our edge devices? External penetration tests examine what is exposed and whether it can be exploited, and configuration reviews assess hardening. Both are worthwhile, particularly after changes.

What to do this week

  • Produce a list of every internet-facing device with its firmware version and support status.
  • Compare it with CISA's Known Exploited Vulnerabilities catalog.
  • Confirm no management interface is reachable from the internet.
  • Check that each device sends logs to your central platform.
  • Identify any device past end of support and schedule its replacement.

How CDT can help

CDT's penetration testing examines your internet-facing attack surface, our system hardening team secures edge device configurations, and cyber hunt looks for signs of compromise when critical vulnerabilities are disclosed.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.