The edge-device incidents in this database divide cleanly, and the corpus has been treating them as one category.
Zero-Day: Nothing The Customer Could Have Done
Ivanti at 25-0109. NetScaler at 25-0624. Managed file transfer at 25-0214. Oracle E-Business Suite at 25-1007 and 25-1003.
In each, exploitation preceded any available fix. The customer’s remaining questions — why internet-facing, why data persisted, whether exfiltration would have been detected — are real, per 25-0214, and none of them is "you should have patched".
Known Defect: A Fix Existed And Was Not Applied
Marquis at 25-0814, where the identifier itself contained the year — CVE-2024-40766, exploited in August 2025. The Congressional Budget Office at 25-1106b.
This is a different failure. Not capacity, not the unpatchable backlog at 26-0405, and not the key-rotation gap at 25-0723 where patching was completed and insufficient. A perimeter device, a published fix, and an interval.
Why The Corpus Conflated Them
Because the structural argument at 25-0805 applies to both: the customer of a sealed appliance has no defence in depth available, no agent to install, no host to harden, frequently no shell.
That argument is correct and it covers only the zero-day case. Where a fix existed, the customer’s available action was precisely the one they did not take — and the corpus weakened its own analysis by folding the two together.
What Follows
For zero-days: architecture. Restrict what the appliance can reach, instrument it as a crown-jewel asset, and assume compromise, per 25-1216.
For known defects: an inventory and a clock. The edge-device population in any organisation is small, enumerable, and the highest-priority patch queue that exists. Graded medium: this is a reclassification of incidents in this database, not a new finding.
It reclassifies the edge-device incidents recorded in this database. Sources below support the underlying cases. Corrections: corrections@forensicpost.com.