The list of products under sustained exploitation through 2025 reads as a catalogue of the security industry: Ivanti Connect Secure, NetScaler ADC and Gateway, Fortinet FortiOS and FortiWeb, SonicWall firewalls. Each appears in this database as the route into an organisation.
Why This Class And Not Others
Three properties combine. The device must be internet-facing, because that is its function. It must parse untrusted input from anyone who can reach it, because that is how it decides who to let in. And it is trusted by everything behind it, because the whole architecture assumes it is doing its job.
A vulnerability in a device with those three properties is worth more than the same vulnerability almost anywhere else, which is precisely why the research attention goes there.
The Customer Cannot Help
For ordinary enterprise software an organisation has options: run it behind something, restrict what it can reach, instrument it, harden the host, sometimes read the source.
A security appliance is a sealed image the vendor controls. There is no agent to install, no host to harden, frequently no shell. The customer’s available actions reduce to applying updates and hoping. That is not negligence — it is the product’s design, sold as an operational benefit.
What Follows, And What Does Not
The conclusion is not that these products should not exist or that removing them would improve anything. An organisation without a remote-access gateway does not have a smaller attack surface; it has a worse one.
What follows is narrower. First, that the appliance deserves the monitoring and network restriction applied to a crown-jewel asset rather than the benign neglect given to infrastructure. Second, that vendors in this category are effectively carrying the security of every customer’s perimeter, and nothing in the commercial arrangement reflects that. The liability files at 26-0419 and 26-0223 record how little consequence attaches.
Graded medium: the pattern is clear from the 2025 record, and the corpus cannot establish whether this class fails at a higher rate than comparable software or is simply attacked far more.
Built on published 2025 vulnerability reporting, listed below, read against the exploitation files in this database. We do not compare defect rates between product categories, as we have no basis to. Corrections: corrections@forensicpost.com.
- Lessons from 2025: zero-day exploitation shaping 2026Outpost24
- Vulnerability report for the year 2025Vulnerability-Lookup
- Top zero-day vulnerabilities exploited in the wild in 2025Cybersecurity News