Skip to content
The Cyber Security Place

Defence

Network security in 2026: the box you bought to keep them out

The appliance guarding the frontier is now the most attacked machine you own, and it is the one piece of equipment on the network where you cannot install anything to watch what it is doing.

Last reviewed August 25, 2026

Edge appliances and remote access concentrators leapt from about 3% to some 22% of exploitation-driven breaches in twelve months, and exploitation of a flaw overtook stolen credentials as the leading way in for the first time in 19 years of that dataset. Median time from advisory to mass exploitation on this equipment is zero days, while makers average roughly 15 days to publish a fix for something already under attack. Of 181 edge flaws seen exploited in one year, under a quarter reached the public catalogue most teams prioritise from, and 42.5% hit hardware past end of life. Around half of observed activity is state-aligned, which means access is kept rather than cashed in, and dwell time runs long because no agent can be installed to notice. The cheapest control is removing the management interface from the internet.

Can you win the patch race?

Build the response out of its stages and see where it lands. Every stage is defensible; the question is what the sum comes to, measured against a starting gun that fired on the day of publication.

Worked exampleAn advisory lands. When are you covered?

5.0days until you are covered
5.0days of exposure after attempts begin
day 0 — attempts beginyou are covered10d20d30d40d
Four response profiles, same advisory
ProfileNoticeConfirmWindowApplyCovered on day
A team that watches the feed4h8h24h4h1.7
A well-run department24h16h72h8h5.0
Quarterly maintenance72h40h720h8h35.0
Nobody owns the device240h120h2160h8h105.3

Every stage above is defensible on its own, and the fastest realistic profile still arrives after attempts have started, because for this class of device the median time from advisory to mass exploitation is zero days. That is the argument: the shortfall is arithmetic rather than negligence, and the useful response is to shrink what an attacker reaches during the window rather than to promise a faster window.

Nothing in that arrangement is a failing. Somebody has to read the advisory, somebody has to establish which units are affected, and a concentrator carrying every remote worker does not get rebooted on a Tuesday afternoon because a bulletin arrived. Each interval is the shortest a competent department can honestly promise, and the total still arrives late.

Tick the box for firmware that has not shipped and the picture changes character rather than degree. You are then in a period during which the flaw is public, attempts are running, and no action exists that would fix it — a state that the language of patch management has no word for, because that language assumes a remedy exists and the only variable is your speed in applying it.

Which is why the productive question is not how to compress the timeline. It is what an intruder reaches during a window you cannot close, and every useful control in the rest of this page is an answer to that instead.

The year exploitation passed stolen credentials

Two figures from the same annual analysis are worth putting side by side, because together they describe a change of era rather than a bad twelve months.

The first is that exploitation of a flaw became the leading route into organisations, ahead of stolen credentials, for the first time in nineteen editions of that report. Credential theft has been the dominant story of this whole archive. Displacing it is not a routine fluctuation.

The second explains the first. Edge equipment and remote access concentrators went from roughly three per cent of exploitation-driven breaches to about twenty-two, a sevenfold rise in a single year. The change of leading vector is almost entirely this category arriving.

The reason is unglamorous and structural. These units sit at a boundary by design, they answer to anybody who can reach them, they run software nobody outside the manufacturer has read, and every organisation of a given size runs one of a handful of models. A working technique against one of those models is a technique against thousands of organisations at once, which is an economic proposition of a different kind from stealing passwords one at a time.

Why is the frontier the softest part of the estate?

Four properties combine, and the combination is what makes this category behave unlike anything else you operate.

Nothing of yours can run on it. The appliance is a closed system with a restricted shell or none at all. The endpoint tooling that watches every laptop and server has nowhere to install itself, so the most heavily instrumented estate in the world has a blind spot exactly where the traffic enters.

It is meant to be reachable. A server can be moved behind something. The whole purpose of a remote access concentrator is that people who are not on your network can arrive at it, which forecloses the usual remedy of taking the thing off the internet.

Downtime is unusually expensive. Rebooting this unit disconnects everybody working remotely, so the change window is scarcer and further away than for almost any other component, and that scarcity is what stretches the timeline above.

The population is concentrated. A small number of models cover most of the market, so a single technique scales in a way that nothing about desktop software does any more.

No one of those is remarkable. Together they describe equipment that is exposed by design, unobservable by construction, awkward to update, and worth attacking at scale — which is a fair summary of why the figures moved as they did.

What the catalogue does not list

One year, 181 edge flaws observed under attack, cut two ways. Both cuts are uncomfortable for the way most teams decide what to fix first.

Listed in the public catalogue of known exploited flaws23.7% listed76.3% not listedAffecting a device still supported by its maker57.5% supported42.5% end of life

The upper strip matters because of how the catalogue is used. It was built as a list of flaws known to be exploited, and it works well for that. It has since been adopted, informally and almost universally, as the answer to what should we fix first — and on this class of equipment under a quarter of what was actually attacked ever reached it. A team working diligently from that list was addressing a minority of its real exposure while believing otherwise.

The lower strip is worse, because it describes work that cannot be done. Two fifths of these flaws affected hardware whose manufacturer had already stopped supporting it. There is no update to apply, no urgency that changes anything, and the only remediation is replacement — which moves the problem from an operational queue to a capital budget, where it competes with everything else and usually loses.

Put together, the two strips say something specific about prioritisation. A process driven by public catalogues and vendor advisories will systematically miss this category, not because the process is careless but because the inputs do not cover it. What covers it is an inventory of what you expose, with a support end date against every line.

How do you detect a compromise you cannot instrument?

By giving up on the box telling you and watching what it does. Four sources are available on equipment that permits nothing to be installed, and all four are already in most organisations.

What it connects to. An appliance has a small, boring set of destinations it legitimately reaches. A connection it initiates to somewhere new is among the highest-quality signals available anywhere in security, precisely because normal behaviour is so narrow. Flow records answer this without touching the device.

Its configuration, compared with yours. Keep the intended configuration in version control and compare nightly. An account that exists on the unit and not in your copy is not an anomaly to be scored; it is an answer.

Its own logs, shipped somewhere it cannot reach. Anybody who takes the device can edit logs stored on it. The same records sitting on a system the appliance has no credentials for are evidence rather than a courtesy.

Its exposed surface, seen from outside. Scan your own perimeter the way anybody else would, on a schedule, and compare with last month. The management panel that appeared in April did not appear because somebody decided to expose it; it appeared because a firmware update reset a default.

None of that is sophisticated and none of it needs a purchase. It is unfashionable because it produces no dashboard, and it is the only visibility available on the machines that now matter most.

A decade guarding the wrong direction

717 reports were filed here, and what they are about is as informative as how many there are.

Reports in this section, by year
2015201620172018201920202021
69651001611916635

Denial of service dominates the decade, appearing in 79 of these reports — more than any other subject in the section by a wide margin. Read them in order and the perimeter is consistently something being pushed against: volumetric floods, amplification, capacity, absorption, the arms race of how many terabits anybody could throw.

That framing was correct for its period and it is not the story now. The perimeter of 2026 is not being pushed against; it is being walked through. The device is not overwhelmed, it is authenticated to — or, more often, not authenticated to at all, because the flaw skips that part.

A10 Thunder SPE: Security and policy enforcement appliance for ADCs and CGNs ran in August 12, 2014 and is representative of the register: a question about magnitude and endurance. Nothing in that framing prepares an organisation for an intrusion in which the boundary equipment behaves normally throughout, because it has not been attacked in the sense anybody was rehearsing.

The category that grew into the current problem is present but slight — Tens of thousands of home routers at risk with duplicate SSH keys, February 19, 2015. Boundary hardware appears across the decade as a curiosity for researchers rather than as the principal way in, which is what it has since become.

Who patches a device nobody sells patches for?

Nobody does, and the honest planning consequence is that this equipment has a disposal date rather than a maintenance schedule.

The economics that produce this are entirely predictable. Boundary hardware is sold once, outright, into a purchase decision made on capability and price. It is installed by somebody who then leaves. Its product line is discontinued after four or five years while the unit runs for ten or twelve, because it still does what it did on the day it was fitted and nothing about it visibly ages. There is no revenue attached to maintaining firmware for a model nobody can buy.

What makes this category different from the general problem of ageing equipment is the exposure. An unsupported switch in a wiring cupboard is a manageable risk. An unsupported concentrator answering the internet is a published invitation, and two fifths of the exploited flaws in the analysis above landed on exactly that.

The practice worth adopting is small and rarely done. Record the support end date for every internet-facing unit at the moment of purchase, in the same place as the asset itself, and treat that date as a replacement date rather than as a warning. Budgets accommodate a dated line item; they do not accommodate an argument about risk, and the difference between those two framings is most of why these devices stay in service.

Does zero trust actually help here?

The architectural idea helps enormously. The product category sold under the name helps considerably less, and separating the two is worth the paragraph.

The idea is that arriving through the concentrator should confer nothing. Reaching an internal service requires proving who you are to that service, every time, regardless of which side of any boundary the request came from. Applied properly, that removes precisely the prize an intruder obtains by taking the appliance: a position on the inside from which everything is reachable.

It is genuinely the right answer to this problem, and it is a multi-year programme touching every internal service, which is why so few organisations have finished one. The version most have deployed covers the applications that were easy and leaves a flat network behind them, so the appliance still yields a foothold that reaches file shares, directory services and management planes.

The failure mode to watch for is buying a replacement gateway and calling it done. A device that terminates every connection and mediates every access is architecturally the same object as the one this page is about, sold with newer vocabulary, and it will appear in these figures in its turn. What reduces exposure is that internal services stop trusting the network, not that the network has a different brand of frontier.

For anybody who cannot commit to the full programme, the useful partial move is to pick the three internal services that would hurt most and put real authentication in front of those, rather than to spread a thin layer everywhere. Partial coverage chosen by consequence is worth considerably more than partial coverage chosen by whichever team said yes first, and it is the version that survives a change of budget.

What changes when the intruder is not after money

Roughly half of the observed exploitation of this equipment is attributed to state-aligned operations, and that changes what a compromise looks like from the inside.

Criminal intrusions announce themselves eventually, because the business model requires it: files are encrypted, a demand appears, the incident becomes an incident. Detection frequently happens because the intruder wanted it to. Strip that away and the compromise has no natural end — the objective is to remain, quietly, for as long as the access is useful.

On boundary equipment that objective is unusually easy to meet. There is no agent to evade because none can be installed. Reboots are rare, so implants that live in memory survive for months. Traffic to and from the unit is expected and voluminous. Several publicly documented cases involved presence measured in months or years, discovered through a firmware verification exercise rather than by an alert.

For most organisations the practical implication is not to plan for a national adversary. It is that dwell time on this equipment is long by default, so the question worth asking is not whether an alert fired but whether anybody has ever checked. A firmware integrity check on an internet-facing concentrator is a morning of work and it is not in most annual plans.

There is a second implication that organisations of every size can act on, and it concerns what happens after a replacement. An intruder who held a concentrator for a year did not spend that year idle: they collected the credentials passing through it, the directory account it authenticated with, and the certificates it presented. Swapping the hardware closes the door and leaves all of that in circulation, which is why a replacement carried out as an equipment refresh rather than as an incident response tends to be followed, some months later, by an intrusion that arrives through the front door with valid credentials and no flaw involved at all.

Designing for equipment you assume is compromised

Since the window cannot be closed, the controls that matter are the ones that limit what an intruder obtains while it is open. Four, in order of return.

Take the management panel off the internet. A large share of these intrusions begin at an administrative interface exposed for convenience. Restricting it to an internal path or a separate access route removes the entry point without depending on anybody's firmware, and it is an afternoon of work.

Put the device on its own segment. Treat everything it can reach as the blast radius, because that is what it is. Most concentrators sit with unrestricted access to the internal network for no reason beyond it being the default at installation.

Give it credentials that expire and are not reused. The account the appliance uses to reach the directory is frequently privileged, permanent and identical to the one on the other four units.

Ship its logs somewhere it cannot write. This costs nothing and is the difference between an investigation and a shrug, because logs stored on a device under somebody else's control are not evidence.

Where to start on a Monday

Three checks, all of which use tooling you already have, and all of which reliably surface something within a morning.

Scan your own perimeter from outside and read the list. Not the intended list — the actual one. Almost every organisation doing this properly for the first time finds a management interface answering the internet, and it is usually on the unit nobody has logged into for two years.

Put a support end date against every internet-facing device. One column. The rows already in the past are your replacement programme, and the point of writing it as a date is that a date can enter a budget.

Ask what each appliance connects to, and check. Pull a week of flow records for the boundary units. The destinations should be a short and boring list, and any surprise in it is worth an afternoon before anything else on this page.

After those the harder work is genuinely prioritisable: segmenting the units, removing shared privileged accounts, and moving internal services off the assumption that arriving through the concentrator means anything. An organisation that has done the first three knows what it exposes and for how much longer it can be maintained, which is more than most can say about the machines now leading the figures.

One caution about sequencing, because the order tends to get reversed. Do the outside scan before the inventory rather than after it, since the inventory records what somebody intended to deploy and the scan records what answers. Where those two disagree, the scan is right, and the disagreement is usually the finding worth acting on first.

Common questions

What counts as an edge device here?

Anything terminating a connection from outside: remote access concentrators, firewalls, gateways, load balancers, file transfer appliances, routers. The defining property is that it is reachable from the internet by design and runs software you cannot inspect.

How large is the shift towards attacking them?

Edge equipment and remote access concentrators went from about 3% to roughly 22% of exploitation-driven breaches in a single year, a sevenfold jump. In the same period exploitation of a flaw overtook stolen credentials as the leading way in, for the first time in nineteen years of that dataset.

How quickly are these flaws attacked?

For this class of equipment the median time from advisory to mass exploitation is zero days: scanning frequently starts within hours of publication, sometimes before fixed firmware exists. Across vulnerabilities generally, roughly 23% see exploitation inside 24 hours and around 55% inside a week.

Is patching faster the answer?

It helps and it cannot close the gap. Assemble the fastest defensible response — notice, confirm, schedule, apply — and the total still lands after attempts have begun. Where no fixed firmware has shipped, the vendor's own turnaround adds a fortnight before the clock even starts.

Why can these devices not be monitored like servers?

Because you cannot install anything on them. The operating system is closed, the shell is restricted or absent, and the endpoint tooling every other part of the estate relies on has nowhere to run. Visibility has to come from outside the box: its own logs shipped elsewhere, network records, and configuration comparison.

Does the public catalogue of exploited flaws cover this?

Only partly, which matters because many organisations treat it as the priority list. Of the network edge flaws seen exploited in one recent year, under a quarter appeared in it. Working solely from that catalogue leaves most of this category unaddressed.

What about devices the manufacturer no longer supports?

They account for roughly two fifths of exploited edge flaws in the same analysis, and for those no fix will ever arrive. Replacement is the only remediation, which turns a security decision into a capital expenditure conversation and is why so many stay in place.

Who is actually exploiting these?

A large share of observed activity is attributed to state-aligned operations — around half in one analysis — with edge appliances making up a substantial slice of everything actively exploited. That changes the calculation, because those operators keep access rather than monetising it quickly.

Does zero trust help with this?

The architecture helps a great deal and the product category helps less than advertised. Removing the assumption that anything arriving through the concentrator is trusted is exactly right. Buying a gateway that itself terminates every connection reproduces the problem with a newer badge.

How would we know if an appliance were already compromised?

Mostly by what it does rather than by what it reports: connections it initiates that it has no business initiating, configuration that differs from your source of truth, accounts that exist and should not, sessions at hours nobody works. All of that is observable from the network side.

What is the single most effective control?

Take the management interface off the internet. A large share of these intrusions begin at an administrative panel that was exposed for convenience, and restricting it to an internal path removes the entry point without waiting for anybody's firmware.

How long should one of these devices last?

Ask for the support end date before purchase and treat it as the replacement date. Hardware of this kind is routinely kept for a decade, and the second half of that decade is frequently spent without any prospect of a fix.

Network and infrastructure coverage

717 reports, newest first. Most cited sources: helpnetsecurity.com (155), infosecurity-magazine.com (63), itproportal.com (39), itsecurityguru.org (22), securityweek.com (19), informationsecuritybuzz.com (18).