The devices built to protect your perimeter have become the most targeted way through it.
In the latest analysis from Suzu Labs, Jacob Krell breaks down why firewalls, VPN gateways, and secure access appliances represent the single most consistently targeted category of enterprise tech:
- 🚨 1 in 4 active exploits in 2026 stem from security & network infrastructure vendors, the highest proportion since the CISA KEV catalog launched.
- 🎯 21 zero-days targeted security and networking products in 2025 alone (per Google’s Threat Intelligence Group).
- 🔓 Ransomware Entry Points: 75 security appliance KEV entries are directly tied to known ransomware campaigns.
- ⚡ Compressing Windows: Exploitation windows have shrunk from weeks to days, driven largely by state-aligned threat actors.
Security appliances sit directly on the internet, hold elevated network trust, and run complex proprietary stacks that resist independent review. Treating these zero-days as standard "software bugs" rather than structural architectural risks leaves teams reacting to the same fire over and over.
Read the full breakdown and methodological analysis on the Suzu Labs blog:
na2.hubs.ly/H07gBh10