A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.
The study, which combined Tenable's exposure telemetry from thousands of customer environments with SentinelOne's digital forensics and incident response (DFIR) casework across 66 CVEs, found a 79% overlap in the vendor attack surfaces observed by both systems, despite minimal CVE-level overlap. This indicates a consistent focus on specific vendors by a diverse range of threat actors.
Twelve CVEs in the combined dataset were confirmed to have multi-nexus attribution, meaning both state-sponsored and criminal actors independently exploited the same vulnerability. These cases spanned five nexus categories: China, Russia, DPRK, Iran, and ransomware. Examples include CVE-2026-15409 in SonicWall SMA1000, exploited by an unattributed actor and ransomware groups; CVE-2023-42793 in JetBrains TeamCity, targeted by Russia's APT29 and DPRK's Lazarus; CVE-2024-3400 in PAN-OS GlobalProtect, exploited by a China-nexus actor and ransomware operators; and CVE-2024-24919 in Check Point Quantum, targeted independently by China's PurpleHaze and Iran's Fox Kitten. The remaining eight multi-nexus CVEs affected products from Fortinet, Citrix, Cisco, and Ivanti.
The analysis highlighted that certain product lines are repeatedly exploited. Ivanti EPMM and Ivanti Connect Secure, for instance, show a new exploited CVE emerging roughly every 8.5 to 13 months, indicating a structural rather than episodic vulnerability-to-exploitation pipeline.
Regarding vendor exposure, F5 products were found to have at least one exposed, actively exploited CVE in 54% of customer environments. Fortinet, often associated with edge device attacks in media, was mid-pack with 25% container-grain exposure, similar to Check Point, Ivanti, and Citrix. Citrix customers exhibited the slowest remediation patterns, with a median time to patch of 461 days.
A significant finding was that high-priority CVEs take longer to remediate, not less. Across Tenable's list of 238 high-priority CVEs, the median remediation time was 146 days, a 24-day gap compared to the 122 days for all other CVEs. This delay creates extended windows of opportunity for attackers. External data, including the 2026 Verizon Data Breach Investigations Report (DBIR), corroborates this trend, noting an increase in median patch time and that only 54% of edge device KEVs were fully remediated.
The difficulty in patching edge devices is attributed to several factors: they are network boundaries, meaning updates can cause downtime; they often don't run standard endpoint agents; they may require firmware-level updates with manual validation; and they frequently lack active support contracts. These operational challenges mean that the devices most critical to patch are often the hardest to update.
The study concludes that defending against one category of threat actor on edge devices necessitates defending against all, as the attack surface is shared. Organizations are advised to implement multiple defense-in-depth strategies, including rapid patching, minimizing the attack surface through feature-set minimization, and running endpoints in protect mode to mitigate lateral movement from initial access compromises.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets