Desk live·
ForensicPost
Cloud/Analysis/File 25-0805

Every Device on This List Was Sold as a Security Product

Ivanti, NetScaler, Fortinet, SonicWall. The 2025 exploitation record is dominated by the appliances organisations bought to protect their perimeter.

Constructed geometry · not a chart of case data
TargetSecurity appliance estates
ActorMultiple
D. Kennedy12 min readConfidence: medium3 sources reviewed

The list of products under sustained exploitation through 2025 reads as a catalogue of the security industry: Ivanti Connect Secure, NetScaler ADC and Gateway, Fortinet FortiOS and FortiWeb, SonicWall firewalls. Each appears in this database as the route into an organisation.

Why This Class And Not Others

Three properties combine. The device must be internet-facing, because that is its function. It must parse untrusted input from anyone who can reach it, because that is how it decides who to let in. And it is trusted by everything behind it, because the whole architecture assumes it is doing its job.

A vulnerability in a device with those three properties is worth more than the same vulnerability almost anywhere else, which is precisely why the research attention goes there.

The Customer Cannot Help

For ordinary enterprise software an organisation has options: run it behind something, restrict what it can reach, instrument it, harden the host, sometimes read the source.

A security appliance is a sealed image the vendor controls. There is no agent to install, no host to harden, frequently no shell. The customer’s available actions reduce to applying updates and hoping. That is not negligence — it is the product’s design, sold as an operational benefit.

What Follows, And What Does Not

The conclusion is not that these products should not exist or that removing them would improve anything. An organisation without a remote-access gateway does not have a smaller attack surface; it has a worse one.

What follows is narrower. First, that the appliance deserves the monitoring and network restriction applied to a crown-jewel asset rather than the benign neglect given to infrastructure. Second, that vendors in this category are effectively carrying the security of every customer’s perimeter, and nothing in the commercial arrangement reflects that. The liability files at 26-0419 and 26-0223 record how little consequence attaches.

Graded medium: the pattern is clear from the 2025 record, and the corpus cannot establish whether this class fails at a higher rate than comparable software or is simply attacked far more.

This is an analysis file

Built on published 2025 vulnerability reporting, listed below, read against the exploitation files in this database. We do not compare defect rates between product categories, as we have no basis to. Corrections: corrections@forensicpost.com.

Sources
  1. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
  2. Vulnerability report for the year 2025Vulnerability-Lookup
  3. Top zero-day vulnerabilities exploited in the wild in 2025Cybersecurity News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary