A coordinated wave of exploitation against edge VPN and firewall appliances from Palo Alto Networks, Fortinet, Citrix and Check Point has become the dominant initial-access vector reported through 2026.
Named components include the Fortibleed credential-compromise campaign against internet-facing FortiGate firewalls, active exploitation of the Palo Alto GlobalProtect authentication bypass CVE-2026-0257, Qilin-linked exploitation of Check Point VPN via CVE-2026-50751, and rapid abuse of a NetScaler memory-disclosure flaw, CVE-2026-8451.
Why This Class Of Device Keeps Failing
Perimeter appliances share a set of properties that make them unusually attractive and unusually hard to defend. They must be reachable from the internet to do their job. They terminate untrusted connections, which means parsing hostile input before authentication. They run vendor firmware that customers cannot inspect. And they are frequently excluded from endpoint monitoring, because they are not endpoints.
The result is a device with the largest possible attack surface and the least possible visibility, sitting at the point of highest trust.
Reconnaissance Precedes The Campaign
A February 2026 scan measurement recorded over 84,000 reconnaissance sessions against SonicOS devices in four days. Activity of that kind is not opportunistic noise; it is target mapping ahead of a campaign, and it is observable before exploitation begins.
Very few organisations treat a spike in scanning against their own perimeter as an actionable signal. It is usually filtered out precisely because it is constant.
Both Ends Of The Adversary Spectrum, Same Door
This category is where state-aligned operations and ransomware affiliates converge. The espionage groups filed in 26-0715 and 26-0601 use edge devices for durable quiet access; ransomware affiliates use the same flaws for revenue.
For a defender that convergence is clarifying. The remediation does not vary by adversary: know which appliances you run, know their support status, keep management interfaces off the public internet, and treat firmware currency as an operational metric rather than a project.
Compiled from published research and reporting, listed below. CVE identifiers and campaign names are as published; device counts vary between sources and we give them as reported. We have not independently verified exploitation counts. Corrections: corrections@forensicpost.com.