5. September 2026 · Cybersecurity

Your Perimeter Device Is the Way In

Abstract editorial header: a luminous barrier wall at the edge of a dark grid, with a bright stream of light passing through it and spreading inward

What CISA’s exploitation catalogue says once you stop counting vulnerabilities and start counting consequences

Executive Summary

Strategic context

Situation. Organisations place security and network appliances at the internet edge, where they terminate encrypted sessions, hold credentials and run large privileged codebases. Those devices are then frequently exempt from the patch discipline applied to servers, because taking them down interrupts everyone.

Complication. The obvious way to assess this, counting each vendor’s vulnerabilities, produces a misleading ranking dominated by install-base size. A different measure in the same public dataset produces a stable and uncomfortable answer.

Question. How exposed is the network edge, measured in a way that survives scrutiny, and what follows for patch governance, procurement and incident planning?

Key findings

1. Measured by consequence rather than count, edge products stand out. In the CISA KEV catalogue (version 2026.09.04, 1,695 entries, counted directly from the machine readable feed), 20.9 per cent of all entries carry confirmed ransomware use. For the edge and appliance vendor group the figure is 35.9 per cent. So what? The question is not whether your edge vendor has vulnerabilities. Every vendor does. It is that vulnerabilities in this category are disproportionately likely to end up in a ransomware campaign.

2. Counting vulnerabilities produces the wrong ranking, and Cisco proves it. Cisco has 96 entries in the catalogue, more than three times Fortinet’s 29. Its ransomware share is 6 per cent against Fortinet’s 48 per cent. So what? Any vendor comparison built on entry counts measures portfolio size and years in the catalogue. It does not measure risk, and a procurement decision made on that basis is measuring the wrong thing.

3. Patching is sometimes explicitly not sufficient, and the vendor says so. Barracuda’s own advisory for CVE-2023-2868 states: “Compromised ESG appliances must be immediately replaced regardless of patch version level.” The company provided replacement hardware at no cost. So what? An incident plan whose only branch is “patch and continue” has no branch for the case the manufacturer itself recommends. Replacement lead time and interim connectivity are not improvised well under incident conditions.

4. The exposure window in that case was about seven months. Barracuda identified the vulnerability on 19 May 2023. Its own advisory records: “Earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022.” So what? Detection at the edge is the constraint, not patch speed. No patch cadence closes a window that opens before anyone knows the window exists.

5. There is no trend here, and claiming one would be reading noise. The edge group’s share of newly added catalogue entries per year runs 12.5, 9.2, 15.5, 21.0, 18.4 and 13.3 per cent for 2021 through 2026. So what? The finding is a level, not a direction. Anyone telling you edge exposure is rising is describing a slope this data does not contain.

Critical recommendations

Priority Recommendation Effort Timeline
High Define a patch cadence for edge appliances separately from servers, with a named person allowed to call an emergency window Low Immediate
High Verify that management interfaces are actually not internet reachable, by scanning rather than by asking Low Immediate
High Add a “replacement, not patching” branch to the incident plan, including lead time and interim connectivity Medium One quarter
Medium Confirm that edge devices forward telemetry capable of showing their own compromise, and that someone reads it Medium One quarter
Medium Before consolidating onto one fabric, test the plan for a vulnerability in that fabric’s own management layer High Before next renewal

Bottom line

Changing edge vendor changes the name in the table, not the structural exposure. What changes the exposure is patch cadence at the edge, detection that covers the device itself, and an incident plan that contains the word “replace”.

How this was measured

The CISA Known Exploited Vulnerabilities catalogue lists vulnerabilities with confirmed real-world exploitation. Presence in it is not a severity score, it is an observation. Each entry carries a field recording whether the vulnerability is known to have been used in ransomware campaigns, which makes a second, better question answerable.

All figures below were extracted directly from the machine readable feed, catalogue version 2026.09.04 with 1,695 entries, on 5 September 2026. They are reproducible by anyone with the same file.

The vendor group, stated so it can be disputed: Fortinet, Ivanti, Citrix, SonicWall, Palo Alto Networks, Barracuda, Sophos, WatchGuard, Zyxel, Check Point, F5, Pulse Secure, Array Networks, Juniper, SolarWinds, Progress, Accellion, QNAP, Synology, Netgear, D-Link, TP-Link. Microsoft, Apple, Adobe and Oracle are excluded as operating system and application vendors. Cisco is deliberately excluded, despite its edge portfolio, because its entries span routing, telephony, collaboration and management software; including it would blur the category being tested.

Finding 1: Consequence, not count

Population Entries Confirmed ransomware use Share
Whole catalogue 1,695 354 20.9 %
Edge and appliance vendors 231 83 35.9 %
Microsoft 386 115 29.8 %

A vulnerability in an edge appliance is roughly 1.7 times as likely to appear in a ransomware campaign as the catalogue average. That is not a statement about code quality. It is a statement about position: these devices sit where an attacker wants to be, hold credentials worth having, and are reachable without a foothold.

Finding 2: Why the obvious table misleads

Vendor Entries Products Years in catalogue Entries per year Ransomware share
Microsoft 386 72 6 64.3 30 %
Cisco 96 41 6 16.0 6 %
Ivanti 35 15 6 5.8 34 %
Fortinet 29 9 6 4.8 48 %
VMware 26 14 5 5.2 35 %
Citrix 23 12 6 3.8 30 %
SonicWall 19 9 6 3.2 68 %
Palo Alto Networks 15 2 5 3.0 40 %
F5 7 4 6 1.2 57 %

Read as a ranking, this table says Cisco is four times the problem Ivanti is. Read by consequence, it says something close to the opposite. Cisco carries the most entries of any edge-adjacent vendor and the lowest ransomware share in the group. Microsoft’s number reflects the size of its surface, not comparatively worse engineering.

This is why the entry count must never be published as a vendor ranking, and why the share column is the one that carries an argument. Small denominators deserve caution too: Check Point’s 67 per cent rests on three entries and means little on its own.

Finding 3: When patching is not the remedy

The most instructive documented case is not a statistic. In May 2023 Barracuda identified CVE-2023-2868 in its Email Security Gateway appliance, patched all appliances worldwide within a day, and then found that this was not enough.

The advisory is unusually direct for vendor material:

“Compromised ESG appliances must be immediately replaced regardless of patch version level.”

Barracuda provided replacement hardware at no cost, and its later guidance notes that victims who did not replace “may still face risk associated with this”. A second round followed in December 2023 through a vulnerability in a third-party library used by the appliance’s virus scanner.

Two things make this worth an executive’s attention. The manufacturer, against its own commercial interest, told customers the device could not be trusted after patching. And most incident plans have no branch for that instruction: they assume patch, verify, continue.

Finding 4: The window opens before you know it exists

Barracuda identified the vulnerability on 19 May 2023. Its own advisory records the earliest identified evidence of exploitation as October 2022, roughly seven months earlier, and frames that as a current finding in an ongoing investigation rather than a final one.

No patch cadence addresses that interval, because during it there was nothing to apply. What addresses it is detection that covers the appliance itself, which is precisely what edge devices are least likely to have: they frequently do not forward the telemetry that would reveal their own compromise, or forward it somewhere nobody reviews. Compromise of the perimeter is then noticed downstream, by what the attacker does next, and the cost is the time between the two.

Finding 5: A level, not a trend

Year Edge entries All new entries Share
2021 39 311 12.5 %
2022 51 555 9.2 %
2023 29 187 15.5 %
2024 39 186 21.0 %
2025 45 245 18.4 %
2026 28 211 13.3 %

The share moves between 9 and 21 per cent without direction. Reporting this as a rising threat would be reading a slope into noise, and 2026 is a partial year besides. The defensible statement is that the level is persistently elevated relative to the catalogue average, not that it is growing.

Implications for Executives

Vendor selection is the wrong lever. The band is the band. Swapping edge vendors changes which name appears in the table, and the structural properties that make the category attractive to attackers travel with the function, not the logo.

Patch governance for the edge is a separate policy. The systems least likely to be patched promptly are the ones reachable from the internet, because rebooting the device that carries every remote worker is a change window nobody volunteers for. That contradiction needs an owner and a pre-authorised emergency path, not good intentions.

Consolidation has a cost that is rarely priced. Putting firewall, SASE, SIEM, EDR and the management plane on one vendor’s fabric means a vulnerability in the shared management layer touches telemetry, detection and response simultaneously. That is a legitimate trade, and it should be made knowingly rather than by default.

Recommendations

Recommendation Rationale Owner Effort
Separate patch cadence for edge appliances, with a named emergency approver These devices are systematically patched last and reached first Infrastructure and CISO Low
Scan your own perimeter for exposed management interfaces Vendor advisories say repeatedly that these should not be reachable, and repeatedly they are Security operations Low
Add a replacement branch to the incident plan One vendor already told customers patching was insufficient Incident response Medium
Verify edge telemetry reaches a place someone reads Compromise of the device is otherwise detected downstream SOC Medium
Price the blast radius before consolidating onto one fabric A flaw in the shared management layer touches every function at once Architecture High

Executive Dashboard

Question Answer from the data Confidence
Are edge products overrepresented in confirmed exploitation? Yes, 35.9 % ransomware share against 20.9 % catalogue-wide High
Does the vendor with the most entries carry the most risk? No, Cisco has the most entries and the lowest share High
Is edge exposure rising? Not demonstrable, the yearly share moves without direction High
Is patching always sufficient? No, one vendor advised replacement regardless of patch level High
How long can exploitation precede discovery? About seven months in the documented case Medium
Does changing vendor reduce the exposure? Not structurally Medium

Frequently Asked Questions

Does this mean our edge vendor is a bad choice?

No. The finding is about a category, not a supplier. The vendors in the group sit in a band with each other, and the properties that attract attackers, internet reachability, terminated encrypted sessions, stored credentials, privileged code, follow the function rather than the brand.

Why is Cisco excluded from the group?

Because its catalogue entries span routing, telephony, collaboration and management software, so including it would blur the category being tested. It appears in the second table precisely because it is the clearest evidence that entry counts mislead.

Why were Porter’s Five Forces or a PESTEL analysis not used?

They answer questions this study does not ask. This is an analysis of a public exploitation dataset and one vendor advisory, not of industry structure or the macro-environment. Applying those frameworks would have produced sections without evidence behind them.

Can we use the entry-count table to compare vendors?

No, and that is the central methodological point. Counts are not normalised for install base, product breadth or years present in the catalogue. The ransomware share is the column that carries an argument, and even that deserves caution where the denominator is small.

Is the Barracuda case representative?

It is a documented case, not a base rate. It proves the situation exists in which a manufacturer considers patching insufficient, and that an incident plan should anticipate it. It says nothing about how often that happens.

What if we cannot patch the edge quickly for operational reasons?

Then that is the finding, and it belongs in the risk register as a stated position rather than as an accident. The realistic mitigations are compensating detection on the device itself and a pre-authorised emergency window, not an aspiration to patch faster.

Where do these numbers come from and can we reproduce them?

From CISA’s machine readable KEV feed, catalogue version 2026.09.04, 1,695 entries, extracted on 5 September 2026. The vendor group is listed in full above so the count can be repeated or contested.

Appendix: Methodology

Research type. Quantitative analysis of a public authority dataset, combined with primary document analysis of one vendor incident advisory.

Frameworks applied. SCQA for framing. For the data, normalisation by consequence (ransomware share) rather than by volume, plus per-vendor normalisation by years present and distinct products.

Frameworks considered and not applied. Porter’s Five Forces, BCG Matrix, Value Chain and PESTEL, none of which addresses the question. Technology Adoption Curve was rejected because the dataset carries no adoption dimension.

Sources. CISA KEV catalogue, machine readable feed, version 2026.09.04, retrieved and counted 5 September 2026. Barracuda Trust Center advisory on the ESG vulnerability, read in full on 5 September 2026. The Barracuda material is vendor material and its interest is not neutral; its evidentiary weight comes from running against that interest.

Confidence. High for findings 1, 2, 3 and 5, all of which rest on directly extracted figures or verbatim vendor statements. Medium for finding 4, because the seven-month figure is the vendor’s own interim assessment in an investigation described as ongoing.

Limitations.

  1. The catalogue records confirmed exploitation, not all exploitation. Absence from it is not evidence of safety.
  2. The ransomware field records known campaign use. It undercounts by construction, since attribution lags.
  3. The vendor group is a judgement call. It is listed in full so the count can be repeated with a different grouping.
  4. Small denominators make individual vendor shares unstable. Check Point’s 67 per cent rests on three entries.
  5. 2026 is a partial year and its share should not be compared with complete years.

What could not be answered. How many of the edge entries were exploited as zero days versus after a patch was available. That ratio decides whether the answer is faster patching or something else entirely, and the feed does not carry the field.

Update trigger. Re-run when the catalogue version changes materially, and revisit if CISA adds a field distinguishing pre-patch from post-patch exploitation.

Sources

  1. CISA, Known Exploited Vulnerabilities catalogue, machine readable feed, catalogue version 2026.09.04. Retrieved and counted 5 September 2026.
  2. Barracuda Networks, Trust Center advisory on the Email Security Gateway Appliance vulnerability, entries from May 2023 to January 2024. Read 5 September 2026.