For the past two years, headlines about hacking edge devices—firewalls, VPN gateways, and remote access controllers—have largely spotlighted groups tied to China and their favored targets, Ivanti, Fortinet, or Palo Alto Networks.
A joint study by Tenable and SentinelOne adds nuance to that narrative.
The two U.S. publishers cross-referenced two independently built data sets. One comes from Tenable’s telemetry of exposure across thousands of customer environments, while the other stems from DFIR (digital forensics and incident response) investigations conducted by SentinelOne.
Their conclusion emphasizes that far from being the preserve of a single attacker type, edge infrastructure has become a shared hunting ground for five distinct actor categories: China, Russia, North Korea, Iran, and financially motivated cybercriminal groups.
A 79% convergence despite different vulnerabilities
The study’s starting point is counterintuitive.
At the level of common vulnerabilities and exposures (CVEs), the two data sets overlap very little. Of 82 CVEs identified in total, only 17, or 21%, appear in both corpora. In other words, Tenable and SentinelOne largely looked at different flaws.
By contrast, the convergence is striking when it comes to vendors.
Eleven of the fourteen vendors present in Tenable’s corpus also appear in SentinelOne’s incident records, a cross-reference rate of 79%.
Focusing only on edge devices and remote access gear, this convergence hits 100%. The seven vendors identified independently by Tenable in this category (Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware) all appear in SentinelOne’s incident dossiers.
For the two publishers, the reach of this result goes beyond a mere statistical observation.
If the two data sets had converge on the same exact CVEs, the message would be reassuring: patching this handful of flaws would limit risk.
What the numbers show is different and harder to interpret. State actors and financially motivated cybercriminal groups, acting independently, each find their own access path to the same vendors.
Patching the CVE of the quarter does not remove a vendor from the target list.
Twelve flaws exploited by both states and cybercriminals
The study cataloged 93 documented cases of vulnerability exploitation by threat actors, representing around forty identified groups.
Twelve vulnerabilities carry an attribution described as “multi-nexus,” confirmed with the highest level of methodological confidence. Direct evidence shows that a state actor and a cybercriminal actor exploited, independently of one another, the same flaw at the same vendor.
Among the cited examples is a zero-day vulnerability in SonicWall SMA1000 appliances. It was first exploited by an espionage group whose origin could not be determined, before being used by INC ransomware operators.
The same scenario recurs with a flaw in PAN-OS GlobalProtect, Palo Alto Networks’ security system. It was exploited by a China-linked actor, then by INC ransomware operators.
Another example: a vulnerability in Check Point Quantum was exploited separately by a Chinese group and by the Iranian group Fox Kitten.
In total, twelve vulnerabilities display this “multi-nexus” profile. The remaining eight concern products from Fortinet, Citrix, Cisco, and Ivanti.
For the study authors, this convergence changes the game for businesses. A defense engineered to counter state actors does not necessarily shield against cybercriminals: both sides can exploit the same vulnerabilities and cross the same entry points.
F5 at the top of exposure; Citrix, champion of patching delays
On the strictly technical side, Tenable’s telemetry, spanning thousands of customer environments, yields a vendor-by-vendor ranking that challenges some conventional wisdom.
Despite the high media exposure of vulnerabilities affecting its gear, Fortinet sits mid-table with 24.9% of its customer environments exposed to at least one actively exploited vulnerability, a level close to Check Point’s 18.6% and Ivanti’s 24.1%.
Two vendors stand out clearly, but for opposite reasons.
F5 displays the highest exposure rate in the study among robust samples: 53.8% of the 2,784 customer environments using F5 products had at least one known, actively exploited vulnerability that remained unpatched.
Citrix, on the other hand, does not dominate in volume (28.8% exposure) but in duration. The median patching time for its equipment reaches 461 days, and 71% of affected environments still host an unpatched vulnerability a year after disclosure.
Fortinet also appears as the vendor targeted by the greatest number of distinct actors: 29 groups spread across the five nexus categories studied, versus 22 for Citrix and 19 for Ivanti.
An almost automatic vulnerability cycle at Ivanti
The study highlights the recurrence of actively exploited vulnerabilities in Ivanti products. In the EPMM line, a new vulnerability of this kind is observed on average every 8.5 months, compared with 13 months for the Connect Secure line.
For Tenable and SentinelOne, this pace makes the next flaw practically inevitable and should push organizations using these products to budget now for the remediation capacity needed in the coming year.
More broadly, the study notes that vulnerabilities deemed most urgent are not remediation- prioritized any faster than others; in fact, the opposite appears to be true.
Across a list of 238 highly prioritized CVEs tracked by Tenable, the median remediation time reaches 146 days, versus 122 days for all other vulnerabilities. A gap the authors deem statistically significant.
The authors offer several operational explanations. Patching a firewall or VPN gateway may cause service disruption for users who rely on them. These devices also require specific maintenance and validation procedures, and they rarely carry the same security agents as desktops and servers.
Credential theft and lateral movement: what field investigations reveal
The SentinelOne portion of the study, drawn from real-world incident response missions, concretely shows what edge-device compromise enables.
In three separate FortiGate appliance interventions, attackers reached the device-management plane and created unauthorized administrator accounts. In two of these incidents, they also exported device configurations and extracted credentials that could be used to progress laterally in the network.
Another incident concerns an Ivanti Cloud Services appliance compromised in late 2024 by a China-linked actor. The attacker exploited two vulnerabilities (CVE-2024-8963 and CVE-2024-8190) chained together before public disclosure of this combination. After gaining access to the device, the attacker collected SSH keys and other credentials stored there.
Because these appliances do not produce standard security telemetry, investigators had to reconstruct intrusions from authentication logs and traces left in the Active Directory— a difficulty that, according to the authors, illustrates the mismatch between the criticality of these devices and the detection capabilities actually available to them.
The recommendations from both vendors
Tenable and SentinelOne offer five recommendations for organizations.
First, promptly patch the F5 and Citrix appliances that exhibit high exposure and among the longest remediation timelines observed.
Next, reduce the attack surface of these appliances by disabling nonessential functions. Both vendors also advise hardening internal endpoints to limit lateral movement should an attacker breach the perimeter.
The two publishers also urge organizations using Ivanti Connect Secure or EPMM to prepare for another actively exploited vulnerability in these lines within the next twelve months. They also advocate setting edge-device remediation timelines that are shorter than the company’s general standards.
Finally, Tenable and SentinelOne urge not to base patch prioritization solely on the CVSS score. A vulnerability showing signs of active exploitation can indeed have a moderate severity. Organizations should therefore cross-reference multiple indicators, including severity, threat intelligence, and the context of the affected assets.