5. September 2026 · Cybersecurity
Your Perimeter Device Is the Way In
What CISA’s exploitation catalogue says once you stop counting vulnerabilities and start counting consequences
Executive Summary
Strategic context
Situation. Organisations place security and network appliances at the internet edge, where they terminate encrypted sessions, hold credentials and run large privileged codebases. Those devices are then frequently exempt from the patch discipline applied to servers, because taking them down interrupts everyone.
Complication. The obvious way to assess this, counting each vendor’s vulnerabilities, produces a misleading ranking dominated by install-base size. A different measure in the same public dataset produces a stable and uncomfortable answer.
Question. How exposed is the network edge, measured in a way that survives scrutiny, and what follows for patch governance, procurement and incident planning?
Key findings
1. Measured by consequence rather than count, edge products stand out. In the CISA KEV catalogue (version 2026.09.04, 1,695 entries, counted directly from the machine readable feed), 20.9 per cent of all entries carry confirmed ransomware use. For the edge and appliance vendor group the figure is 35.9 per cent. So what? The question is not whether your edge vendor has vulnerabilities. Every vendor does. It is that vulnerabilities in this category are disproportionately likely to end up in a ransomware campaign.
2. Counting vulnerabilities produces the wrong ranking, and Cisco proves it. Cisco has 96 entries in the catalogue, more than three times Fortinet’s 29. Its ransomware share is 6 per cent against Fortinet’s 48 per cent. So what? Any vendor comparison built on entry counts measures portfolio size and years in the catalogue. It does not measure risk, and a procurement decision made on that basis is measuring the wrong thing.
3. Patching is sometimes explicitly not sufficient, and the vendor says so. Barracuda’s own advisory for CVE-2023-2868 states: “Compromised ESG appliances must be immediately replaced regardless of patch version level.” The company provided replacement hardware at no cost. So what? An incident plan whose only branch is “patch and continue” has no branch for the case the manufacturer itself recommends. Replacement lead time and interim connectivity are not improvised well under incident conditions.
4. The exposure window in that case was about seven months. Barracuda identified the vulnerability on 19 May 2023. Its own advisory records: “Earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022.” So what? Detection at the edge is the constraint, not patch speed. No patch cadence closes a window that opens before anyone knows the window exists.
5. There is no trend here, and claiming one would be reading noise. The edge group’s share of newly added catalogue entries per year runs 12.5, 9.2, 15.5, 21.0, 18.4 and 13.3 per cent for 2021 through 2026. So what? The finding is a level, not a direction. Anyone telling you edge exposure is rising is describing a slope this data does not contain.
Critical recommendations
| Priority | Recommendation | Effort | Timeline |
|---|---|---|---|
| High | Define a patch cadence for edge appliances separately from servers, with a named person allowed to call an emergency window | Low | Immediate |
| High | Verify that management interfaces are actually not internet reachable, by scanning rather than by asking | Low | Immediate |
| High | Add a “replacement, not patching” branch to the incident plan, including lead time and interim connectivity | Medium | One quarter |
| Medium | Confirm that edge devices forward telemetry capable of showing their own compromise, and that someone reads it | Medium | One quarter |
| Medium | Before consolidating onto one fabric, test the plan for a vulnerability in that fabric’s own management layer | High | Before next renewal |
Bottom line
Changing edge vendor changes the name in the table, not the structural exposure. What changes the exposure is patch cadence at the edge, detection that covers the device itself, and an incident plan that contains the word “replace”.
How this was measured
The CISA Known Exploited Vulnerabilities catalogue lists vulnerabilities with confirmed real-world exploitation. Presence in it is not a severity score, it is an observation. Each entry carries a field recording whether the vulnerability is known to have been used in ransomware campaigns, which makes a second, better question answerable.
All figures below were extracted directly from the machine readable feed, catalogue version 2026.09.04 with 1,695 entries, on 5 September 2026. They are reproducible by anyone with the same file.
The vendor group, stated so it can be disputed: Fortinet, Ivanti, Citrix, SonicWall, Palo Alto Networks, Barracuda, Sophos, WatchGuard, Zyxel, Check Point, F5, Pulse Secure, Array Networks, Juniper, SolarWinds, Progress, Accellion, QNAP, Synology, Netgear, D-Link, TP-Link. Microsoft, Apple, Adobe and Oracle are excluded as operating system and application vendors. Cisco is deliberately excluded, despite its edge portfolio, because its entries span routing, telephony, collaboration and management software; including it would blur the category being tested.
Finding 1: Consequence, not count
| Population | Entries | Confirmed ransomware use | Share |
|---|---|---|---|
| Whole catalogue | 1,695 | 354 | 20.9 % |
| Edge and appliance vendors | 231 | 83 | 35.9 % |
| Microsoft | 386 | 115 | 29.8 % |
A vulnerability in an edge appliance is roughly 1.7 times as likely to appear in a ransomware campaign as the catalogue average. That is not a statement about code quality. It is a statement about position: these devices sit where an attacker wants to be, hold credentials worth having, and are reachable without a foothold.
Finding 2: Why the obvious table misleads
| Vendor | Entries | Products | Years in catalogue | Entries per year | Ransomware share |
|---|---|---|---|---|---|
| Microsoft | 386 | 72 | 6 | 64.3 | 30 % |
| Cisco | 96 | 41 | 6 | 16.0 | 6 % |
| Ivanti | 35 | 15 | 6 | 5.8 | 34 % |
| Fortinet | 29 | 9 | 6 | 4.8 | 48 % |
| VMware | 26 | 14 | 5 | 5.2 | 35 % |
| Citrix | 23 | 12 | 6 | 3.8 | 30 % |
| SonicWall | 19 | 9 | 6 | 3.2 | 68 % |
| Palo Alto Networks | 15 | 2 | 5 | 3.0 | 40 % |
| F5 | 7 | 4 | 6 | 1.2 | 57 % |
Read as a ranking, this table says Cisco is four times the problem Ivanti is. Read by consequence, it says something close to the opposite. Cisco carries the most entries of any edge-adjacent vendor and the lowest ransomware share in the group. Microsoft’s number reflects the size of its surface, not comparatively worse engineering.
This is why the entry count must never be published as a vendor ranking, and why the share column is the one that carries an argument. Small denominators deserve caution too: Check Point’s 67 per cent rests on three entries and means little on its own.
Finding 3: When patching is not the remedy
The most instructive documented case is not a statistic. In May 2023 Barracuda identified CVE-2023-2868 in its Email Security Gateway appliance, patched all appliances worldwide within a day, and then found that this was not enough.
The advisory is unusually direct for vendor material:
“Compromised ESG appliances must be immediately replaced regardless of patch version level.”
Barracuda provided replacement hardware at no cost, and its later guidance notes that victims who did not replace “may still face risk associated with this”. A second round followed in December 2023 through a vulnerability in a third-party library used by the appliance’s virus scanner.
Two things make this worth an executive’s attention. The manufacturer, against its own commercial interest, told customers the device could not be trusted after patching. And most incident plans have no branch for that instruction: they assume patch, verify, continue.
Finding 4: The window opens before you know it exists
Barracuda identified the vulnerability on 19 May 2023. Its own advisory records the earliest identified evidence of exploitation as October 2022, roughly seven months earlier, and frames that as a current finding in an ongoing investigation rather than a final one.
No patch cadence addresses that interval, because during it there was nothing to apply. What addresses it is detection that covers the appliance itself, which is precisely what edge devices are least likely to have: they frequently do not forward the telemetry that would reveal their own compromise, or forward it somewhere nobody reviews. Compromise of the perimeter is then noticed downstream, by what the attacker does next, and the cost is the time between the two.
Finding 5: A level, not a trend
| Year | Edge entries | All new entries | Share |
|---|---|---|---|
| 2021 | 39 | 311 | 12.5 % |
| 2022 | 51 | 555 | 9.2 % |
| 2023 | 29 | 187 | 15.5 % |
| 2024 | 39 | 186 | 21.0 % |
| 2025 | 45 | 245 | 18.4 % |
| 2026 | 28 | 211 | 13.3 % |
The share moves between 9 and 21 per cent without direction. Reporting this as a rising threat would be reading a slope into noise, and 2026 is a partial year besides. The defensible statement is that the level is persistently elevated relative to the catalogue average, not that it is growing.
Implications for Executives
Vendor selection is the wrong lever. The band is the band. Swapping edge vendors changes which name appears in the table, and the structural properties that make the category attractive to attackers travel with the function, not the logo.
Patch governance for the edge is a separate policy. The systems least likely to be patched promptly are the ones reachable from the internet, because rebooting the device that carries every remote worker is a change window nobody volunteers for. That contradiction needs an owner and a pre-authorised emergency path, not good intentions.
Consolidation has a cost that is rarely priced. Putting firewall, SASE, SIEM, EDR and the management plane on one vendor’s fabric means a vulnerability in the shared management layer touches telemetry, detection and response simultaneously. That is a legitimate trade, and it should be made knowingly rather than by default.
Recommendations
| Recommendation | Rationale | Owner | Effort |
|---|---|---|---|
| Separate patch cadence for edge appliances, with a named emergency approver | These devices are systematically patched last and reached first | Infrastructure and CISO | Low |
| Scan your own perimeter for exposed management interfaces | Vendor advisories say repeatedly that these should not be reachable, and repeatedly they are | Security operations | Low |
| Add a replacement branch to the incident plan | One vendor already told customers patching was insufficient | Incident response | Medium |
| Verify edge telemetry reaches a place someone reads | Compromise of the device is otherwise detected downstream | SOC | Medium |
| Price the blast radius before consolidating onto one fabric | A flaw in the shared management layer touches every function at once | Architecture | High |
Executive Dashboard
| Question | Answer from the data | Confidence |
|---|---|---|
| Are edge products overrepresented in confirmed exploitation? | Yes, 35.9 % ransomware share against 20.9 % catalogue-wide | High |
| Does the vendor with the most entries carry the most risk? | No, Cisco has the most entries and the lowest share | High |
| Is edge exposure rising? | Not demonstrable, the yearly share moves without direction | High |
| Is patching always sufficient? | No, one vendor advised replacement regardless of patch level | High |
| How long can exploitation precede discovery? | About seven months in the documented case | Medium |
| Does changing vendor reduce the exposure? | Not structurally | Medium |
Frequently Asked Questions
Does this mean our edge vendor is a bad choice?
No. The finding is about a category, not a supplier. The vendors in the group sit in a band with each other, and the properties that attract attackers, internet reachability, terminated encrypted sessions, stored credentials, privileged code, follow the function rather than the brand.
Why is Cisco excluded from the group?
Because its catalogue entries span routing, telephony, collaboration and management software, so including it would blur the category being tested. It appears in the second table precisely because it is the clearest evidence that entry counts mislead.
Why were Porter’s Five Forces or a PESTEL analysis not used?
They answer questions this study does not ask. This is an analysis of a public exploitation dataset and one vendor advisory, not of industry structure or the macro-environment. Applying those frameworks would have produced sections without evidence behind them.
Can we use the entry-count table to compare vendors?
No, and that is the central methodological point. Counts are not normalised for install base, product breadth or years present in the catalogue. The ransomware share is the column that carries an argument, and even that deserves caution where the denominator is small.
Is the Barracuda case representative?
It is a documented case, not a base rate. It proves the situation exists in which a manufacturer considers patching insufficient, and that an incident plan should anticipate it. It says nothing about how often that happens.
What if we cannot patch the edge quickly for operational reasons?
Then that is the finding, and it belongs in the risk register as a stated position rather than as an accident. The realistic mitigations are compensating detection on the device itself and a pre-authorised emergency window, not an aspiration to patch faster.
Where do these numbers come from and can we reproduce them?
From CISA’s machine readable KEV feed, catalogue version 2026.09.04, 1,695 entries, extracted on 5 September 2026. The vendor group is listed in full above so the count can be repeated or contested.
Appendix: Methodology
Research type. Quantitative analysis of a public authority dataset, combined with primary document analysis of one vendor incident advisory.
Frameworks applied. SCQA for framing. For the data, normalisation by consequence (ransomware share) rather than by volume, plus per-vendor normalisation by years present and distinct products.
Frameworks considered and not applied. Porter’s Five Forces, BCG Matrix, Value Chain and PESTEL, none of which addresses the question. Technology Adoption Curve was rejected because the dataset carries no adoption dimension.
Sources. CISA KEV catalogue, machine readable feed, version 2026.09.04, retrieved and counted 5 September 2026. Barracuda Trust Center advisory on the ESG vulnerability, read in full on 5 September 2026. The Barracuda material is vendor material and its interest is not neutral; its evidentiary weight comes from running against that interest.
Confidence. High for findings 1, 2, 3 and 5, all of which rest on directly extracted figures or verbatim vendor statements. Medium for finding 4, because the seven-month figure is the vendor’s own interim assessment in an investigation described as ongoing.
Limitations.
- The catalogue records confirmed exploitation, not all exploitation. Absence from it is not evidence of safety.
- The ransomware field records known campaign use. It undercounts by construction, since attribution lags.
- The vendor group is a judgement call. It is listed in full so the count can be repeated with a different grouping.
- Small denominators make individual vendor shares unstable. Check Point’s 67 per cent rests on three entries.
- 2026 is a partial year and its share should not be compared with complete years.
What could not be answered. How many of the edge entries were exploited as zero days versus after a patch was available. That ratio decides whether the answer is faster patching or something else entirely, and the feed does not carry the field.
Update trigger. Re-run when the catalogue version changes materially, and revisit if CISA adds a field distinguishing pre-patch from post-patch exploitation.
Sources
- CISA, Known Exploited Vulnerabilities catalogue, machine readable feed, catalogue version 2026.09.04. Retrieved and counted 5 September 2026.
- Barracuda Networks, Trust Center advisory on the Email Security Gateway Appliance vulnerability, entries from May 2023 to January 2024. Read 5 September 2026.