An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Free security assessment for qualifying organizations — request yours →

Edge devices are the new front door: what 2026’s VPN and gateway zero-days tell us

Check Point VPN in June, Citrix NetScaler in September: attackers keep getting in through the appliances that sit at the edge of the network. This advisory covers what happened, why edge devices are such a reliable target, and the specific steps that reduce exposure.

For most of the last decade, the default mental model of an intrusion started with a phishing email. In 2026, a growing share of serious incidents start somewhere else: the VPN concentrator, remote-access gateway, or application delivery controller sitting at the edge of the network. These devices are internet-facing by design, they authenticate users before anything else does, and they rarely run endpoint detection. When one of them has an exploitable flaw, an attacker can be inside the network without ever touching an inbox.

Two incidents worth studying

Check Point Remote Access VPN (CVE-2026-50751). On June 8, 2026, Check Point disclosed a critical authentication bypass (CVSS 9.3) in its Remote Access VPN, Mobile Access, and Spark Firewall products. Deployments that still accepted the deprecated IKEv1 key exchange and did not require a machine certificate could be made to establish a VPN session without valid credentials. Check Point reported exploitation dating back to May 7, roughly a month before the advisory, and linked at least one incident with medium confidence to a Qilin ransomware affiliate. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Notably, four of the nine affected version branches were already past end of support.

Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772). On September 27, 2026, Citrix disclosed eight NetScaler vulnerabilities, two of them critical remote code execution flaws (CVSSv4 9.5) that were already being exploited as zero-days. The more dangerous of the two works against the default configuration with low attack complexity. CISA added both to the KEV catalog the same day. In one documented case, attackers used the flaw to archive the appliance’s configuration directory into a publicly served web path, exposing admin password hashes, LDAP and RADIUS bind credentials, and SSL private keys to anyone who requested the file.

Why the edge keeps getting hit

Reachability. A VPN gateway has to be reachable from the internet to do its job. Attackers can find every exposed instance of a vulnerable product with a single scan.

Privilege. These devices hold credentials, certificates, and session state for the whole organization. Compromising one often yields keys to everything behind it.

Visibility gaps. Most edge appliances can’t run an EDR agent, and their logs are frequently not forwarded anywhere. An attacker who lands on the appliance may be invisible to the tools the security team actually watches.

Patch friction. Updating a VPN concentrator can mean disconnecting every remote user, so these updates tend to wait for a maintenance window. Both incidents above were exploited before a patch existed, which makes the delay after release even more costly.

What to do now

Know what you expose. Keep an inventory of every internet-facing appliance, including make, model, firmware version, and support status. If you can’t list them, you can’t patch them. TLINK PRO’s exposure scanner and SSL/TLS analyzer are a fast way to see what an outsider sees.

Treat KEV entries on edge devices as emergencies. When an internet-facing product you run appears in CISA’s KEV catalog, patch outside the normal cycle. Plan the outage in advance so the decision is already made when the advisory lands.

Assume compromise before the patch. In both incidents, exploitation started weeks before disclosure. Patching closes the door but doesn’t evict anyone already inside. Review appliance logs back to the earliest known exploitation date, and rotate credentials and certificates stored on the device if there is any doubt.

Retire end-of-support hardware. CISA has published specific guidance on reducing the attack surface of end-of-support edge devices. An appliance that no longer receives fixes will eventually have an unfixable vulnerability.

Disable legacy protocols. The Check Point flaw only affected gateways still accepting IKEv1. Removing deprecated protocols and requiring certificate-based machine authentication shrinks the attack surface before the next advisory, not after.

Get the logs somewhere useful. Forward edge-device authentication and admin logs to a monitored platform so unusual logins, configuration changes, and unexpected file writes are seen by an analyst rather than discovered during the post-incident review.

How ThreatGrid helps

ThreatGrid’s managed detection and response covers edge-device telemetry alongside endpoints and identity, and our analysts track KEV additions against each client’s known asset inventory so exposed appliances are flagged the day an advisory drops. The live threat feed at the bottom of every page and our security bulletins follow the same KEV source. If you’re not sure what your edge looks like from the outside, start with an assessment.

Sources: Check Point advisory sk185033 and Rapid7 analysis of CVE-2026-50751; Citrix bulletin CTX697096, CISA alert of September 27, 2026, and Rapid7 analysis of CVE-2026-88771/88772; CISA guidance on end-of-support edge devices.


Take action

Request an assessment or start a conversation.

ThreatGrid works with organizations at every maturity level — from first MSSP evaluation through active monitoring and incident response.