Edge devices are attacked first, application servers after the patch
EditorialBy TrustList Editorial
Of 30 exploited flaws our desk reported in three weeks, 14 were attacked by the day a fix appeared, ten of them on edge devices, and 11 after a fix existed, nine of them in application servers.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Network Security
- +4 more
About Edge devices are attacked first, application servers after the patch
Edge devices are attacked first, application servers after the patch
Of the 74 security items our desk published between 15 September and 6 October, 54 reported a flaw or a patch in a product that somebody has to install and keep up to date. Counted flaw by flaw, 30 of the flaws in those items were being attacked, and they fall into two groups that need different handling. Fourteen were attacked on or before the day a fix appeared, and ten of those sat on the network edge: access control, VPN and remote-access gateways, SD-WAN consoles, routers, a mail gateway. Eleven were attacked after a fix already existed, and nine of those were in application servers: a content management system, a webmail client, an API gateway, a file server. Five more were exploited, but our items give no date to place them.
The two ends of the second group show how wide the range is. WordPress shipped 7.1.2 on 22 September, and the security firm Patchstack recorded the first exploitation attempt the same day, hours after the release (our item). WSO2 published its fix for an API Manager login bypass on 3 May; the first confirmed attack our item reports came on 13 September, 133 days later (our item). In both cases a patch was sitting available. The gap before attackers used the flaw was a few hours in one and more than four months in the other.
That split is the finding. It says which products to treat as an emergency on the day and which to catch up on every week.
Ten of the fourteen early attacks hit the network edge
The flaws attacked at or before disclosure are the ones where a patch window never existed.
Cisco's Identity Services Engine, the system that decides which users and devices may join a corporate network, carried CVE-2026-76460, an authentication bypass scored 10.0 that Cisco said was already being exploited when it published on 16 September. Cisco said there was no workaround and warned that an attacker with root might remove the evidence (our item). A week later F5 fixed a heap overflow in BIG-IP Access Policy Manager that was being used against OAuth servers, Arista warned that its self-hosted VeloCloud Orchestrator was under attack with fixes for only two of four release trains, and Check Point disclosed a pre-authentication flaw in its Security Management server that it had seen in a handful of targeted attacks.
Then came Citrix. Its bulletin of 27 September covered NetScaler ADC and Gateway, and Citrix said exploits of two of the flaws had been observed. Mandiant later said exploitation began in early September at the latest, and GreyNoise logged a failed attempt on 24 September, three days before the bulletin. When a public proof of concept appeared, targeted attacks turned into internet-wide scanning within minutes (bulletin item, follow-up). A week later a third NetScaler flaw, tied to SAML configurations, arrived with an exploit already circulating. Cisco's Catalyst SD-WAN Manager followed on 30 September with a 9.8 authentication bypass and again no workaround, and on 1 October Fortinet disclosed an exploited FortiMail file-write flaw whose fixed builds were still listed as upcoming when we read the advisory. A MikroTik RouterOS chain that CERT Polska says was used against devices from at least 2 September, a day before the fixes were published, completes the ten.
The four that are not edge devices are the Oracle PeopleSoft flaw first exploited between 27 May and 9 June, Apple's CoreGraphics bug (fixed on 28 September, with a warning that it may have been used in an extremely sophisticated attack on specific individuals), and two Zammad helpdesk flaws that the Dutch Institute for Vulnerability Disclosure found while investigating a breach of its own network.
Two details from these items change what a team should do first. Of the fourteen flaws, our items record a vendor stopgap for two (an F5 iRule, and a Fortinet feature that can be switched off) and a statement that none exists for two more, both Cisco. And exposure often depends on configuration. The F5 flaw matters only on a virtual server carrying both an access policy and an OAuth profile; the third NetScaler flaw only on appliances whose configuration contains one of two SAML commands. A team that can read its own configuration knows on day zero whether it is exposed. A team that cannot has to patch everything.
Evidence matters as much as the version. CISA advised preserving forensic data before updating the NetScalers, because an update can remove it. Installing a fix says nothing about whether someone is already inside.
PeopleSoft shows the other trap. After Oracle's June alert, many organisations put firewall rules on the vulnerable path instead of patching. In late September Google's threat intelligence team reported attackers requesting the same path with one letter percent-encoded, which the firewall rules compared before decoding and PeopleSoft decoded after. Google's summary was blunt: "WAF rules and path-based blocking are not a substitute for patching." Web shells were planted on dozens of systems (our item).
Eleven flaws were attacked after the patch, six within three weeks
For this group we have two dates each: when the fix existed and the first date on which one of our items reports an attack. The gaps, shortest to longest:
- WordPress core: 0 days (22 September)
- Adobe Commerce and Magento, CVE-2026-71362: 1 day (fix 11 August, attack reports 12 August)
- Check Point gateway VPN flaw, CVE-2026-85102: 3 days
- Zimbra, CVE-2026-73570: 8 days
- JetBrains TeamCity, CVE-2026-63077: 9 days (advisory to CISA's listing)
- Dolibarr ERP: 19 days (advisory to the Italian agency's report of attacks)
- SharePoint Server, CVE-2026-65660: 44 days
- Rejetto HFS file server: 81 days (fix to VulnCheck's warning of reconnaissance)
- Zyxel GS1900 switches: 97 days
- Roundcube webmail: 120 days
- WSO2 API Manager: 133 days
The median is 19 days. Six of the eleven were attacked within that time and five after more than six weeks, with nothing in between. A public fix shows an attacker where the flaw is, and our WordPress and Zimbra items read the fast cases that way. Microsoft's analysis of Zimbra is the clearest example in our records. The fix shipped on 20 July in version 10.1.20. Between 28 July and 7 August Microsoft saw two scanning tools probing the vulnerable path, before the CVE was published on 13 August. CISA listed it on 21 August, and attackers went on to plant web shells and send mailbox archives to cloud storage. The flaw is reachable only on servers with an optional SNMP package and notifications enabled (our item).
The slow five look different: a small-office switch, a webmail client that hosting companies choose for their customers, an API gateway, a file server that teams often set up without central IT, and a SharePoint server whose flaw Microsoft first described as spoofing at 6.5. For SharePoint and Rejetto, a public technical write-up came before the attacks. A researcher published full details of the SharePoint flaw on 22 September and the Canadian Centre for Cyber Security reported exploitation on 24 September; Microsoft then revised its own entry to say it had reliable evidence of attacks. The vendor's label had predicted none of this.
One caution: these are the first attack dates our items report, not necessarily the first attacks, so the true gaps may be shorter, particularly for Roundcube and WSO2.
CISA's catalogue is the clock to use. In all 15 listings that our items describe, the federal deadline was three days after the listing date. It binds US agencies only, but CISA asks every organisation to prioritise the list, and a listing is the point where "no known exploitation" stops being true. Adobe said at release that it knew of no attacks on its Commerce flaw; the first attack reports came the next day.
Hosted editions were fixed before the advisory; the copy you run waits for you
In 13 of the 54 vulnerability items the vendor says its own hosted edition is already fixed or was never affected. Atlassian Cloud was patched before the Data Center advisory went out. TeamCity Cloud is not affected by the flaw CISA now links to ransomware. Cisco fixed its managed SD-WAN cloud, Microsoft patched SharePoint Online and Exchange Online, and Citrix, ServiceNow, GitLab, JetBrains and Arista did the same for the editions they host. None of the 54 items described an unfixed flaw in a service the vendor runs.
The cloud appears elsewhere in our records, in a different tense. Six items concern incidents and penalties at services and suppliers: Gyazo, where Helpfeel said about 23.62 million user records were taken after an upload-server flaw was exploited on 11 September; Veradigm; Times Car, with about 6.6 million accounts; a Swedish fine against the HR supplier Miljödata; and the Labcorp settlement (Gyazo item). Customers of a self-hosted product receive a to-do list before anything has happened. Customers of a service receive a notice afterwards. With the hosted edition the job is to ask what was patched and when, because you cannot see it. With the copy you run, the job is to patch it.
The copy you run also has a risk that the hosted one does not: your version may have no fix. Eight items describe customers with nothing to install on the day we reported. Arista had fixes for two release trains of four. FortiMail's fixed builds were upcoming. Ubuntu's standard kernels on 22.04 and 24.04 were still marked vulnerable for one of the Linux flaws on CISA's list. Zammad 6.5 and older are out of support and get no fix, and one of the two Zammad flaws had no fix at all. Older SageMaker Distribution ranges will not be fixed, and ModSecurity listed no fixed version for one bypass flaw.
The sharpest case is Exchange. Microsoft's September V2 update closes CVE-2026-96940, which lets a signed-in user read colleagues' mailboxes. Exchange 2016 and 2019 left support in October 2025, and their security updates between May and October 2026 reach only organisations enrolled in the second period of the paid Extended Security Update programme. Without enrolment the answer is to move to Subscription Edition (our item). Paid extended support appears in four of the 74 items, and in only one of them is it the condition for receiving a security fix.
The same product kinds recur, and AI tooling is new and quiet
Items can touch more than one kind of product, so these counts overlap. Of the 54 vulnerability items, 14 concern network edge equipment, 12 web and business applications, 8 developer tools and libraries, 7 management consoles, 7 security products themselves, 6 mail servers and gateways, 5 AI tooling and 2 file transfer or sharing products.
The management consoles administer many machines at once: Arista's orchestrator, Check Point's management server, SolarWinds Observability, Cisco's SD-WAN Manager, Dell's two management tools and HPE OneView. A flaw in one reaches everything it manages, and three of the seven were in our first group. The security products teach the same lesson: Cisco ISE, F5, Check Point, WatchGuard, Tenable's Nessus and ModSecurity all appear, and Nessus holds credentials for everything it scans.
The five AI-tooling items are the MCP Python SDK, n8n, AWS's Loom agent platform, SageMaker Distribution and GitLab's AI Gateway. None carries an exploitation report in our items. All five are software that customers run or install themselves, and GitLab says its flaw has no workaround. Separately, four items describe AI as attacker or finder: the Zammad intrusion at the Dutch disclosure institute, a Rejetto weakness found with an AI model, South Korean banks hit by suspected AI agents, and an Australian directive citing an AI agent that reached an outdated Medicare portal. Rejetto matters for the routine below: Horizon3.ai found that weakness in June with an AI model doing the mathematics, and attackers' reconnaissance began 81 days after the patch.
Workarounds are rare. Only nine of the 54 items say anything about one: four say there is none and five describe a stopgap. A routine that depends on mitigation will usually have nothing to apply.
A weekly routine with three lanes and a Monday check
Build the inventory by lane, not by vendor. Lane A is anything customer-run that sits on the network edge, administers other systems or decides who may log in: gateways, firewalls, VPN, SD-WAN, access control, mail gateways, management consoles. Lane B is internet-reachable application servers: your website platform, webmail, ERP, helpdesk, file server, API gateway. Lane C is everything internal, including developer tools, libraries and AI tooling. Include the forgotten instances, because the slow group was largely forgotten: old WordPress microsites, a team's file server, a helpdesk test copy.
Lane A: act on the day the advisory appears. Fourteen of the 25 exploited flaws we can date (56 per cent) were attacked on or before the fix, so no weekly cycle fits. On the day, read your configuration to see whether you are in the affected condition; take management interfaces off the internet; apply the vendor stopgap if there is one; copy logs before updating; update; then hunt for the published indicators. Treat an exposed, unpatched appliance as compromised and rebuild it from a clean image, as the Citrix and Cisco guidance says. Ask any provider that runs these for you to confirm the build, the update date and the hunt in writing.
Lane B: patch within seven days when the flaw needs no login. Six of the 11 post-fix attacks began within 19 days and three within three days, so seven days is shorter than the median and longer than the fastest. A flaw that needs a login is no comfort where every employee has one, as SharePoint showed, so the clock applies to any flaw that executes code.
The Monday check catches the slow five. Every Monday, compare your inventory to CISA's exploited-vulnerabilities list, published as a JSON feed. Match on product and version, because a flaw filed as "patch when convenient" can be added weeks later. A match on anything whose fix is more than 30 days old gets a three-day deadline, copied from CISA's own. In our data that rule would have caught Zyxel, WSO2 and SharePoint, each listed at least six weeks after its fix. It would have missed Roundcube and Rejetto, which our items report from a Canadian advisory and a VulnCheck warning, so read your national cyber agency's alerts as well.
Ignore the severity word when setting the timeline. Microsoft first called the SharePoint flaw spoofing at 6.5. Use exposure (can an unauthenticated visitor reach it), the position in the network and the exploited list.
Keep an end-of-support list beside the patch list. Our items give dates that belong on it: Office LTSC 2021, Project and Visio on 13 October, Windows Server 2012 and 2012 R2 Extended Security Updates year 3 on the same date, Exchange 2016 and 2019 already limited to paying customers, SharePoint 2016 and 2019 out of support since July 2026, and Zammad 6.5 and earlier. For each, decide before the next advisory whether you will pay, migrate or isolate.
Re-read what you parked. "No exploitation known" is a status with a date on it. Fifteen of our 54 vulnerability items say so and thirteen say nothing either way. Re-check them every Friday against the same list, because Adobe's flaw changed status within a day of release.
How we counted this
We took the 74 items our desk published on the security theme between 15 September and 6 October 2026 (the earliest is dated 20 September) and counted them with a script, whose raw output is in the companion method file. Each item was read and coded by hand: 54 vulnerability or patch items, 4 incident disclosures, 10 regulator or guidance items, 5 lifecycle items and 1 grants call that is in no count. Exploited flaws were counted at CVE level, 30 across 23 products. "Attacked on or before the fix" means an item reports exploitation at or before the vendor's disclosure or fix. "Attacked after the fix" means an item gives both a fix date and a later first attack date.
The limits are real. The counts cover what our desk published, which depends on what we read, not every flaw disclosed. Attack dates can lag the real first attack. Five exploited flaws (three in the Linux kernel, Acronis Backup and a second Adobe Commerce flaw) have no usable date and sit outside the 14 and the 11. Our items disagree in two places: they give two first-probe times for the WordPress flaw on 22 September, and the WSO2 fix date is April in one source and 3 May in the advisory, which we used. Twenty-six of the 74 items carry a red note for a verification gap. Four exploited flaws rest only on red-noted items (Zimbra, Dolibarr, Rejetto and the third NetScaler flaw). Without them the counts are 13 early and 8 after the fix, with a median gap of 26.5 days across eight values, and the two-group shape holds.
Sources
Our items:
- Cisco ISE, F5 BIG-IP APM, Arista VCO, Check Point
- NetScaler bulletin, follow-up, SAML flaw
- Cisco SD-WAN Manager, FortiMail, SharePoint and MikroTik
- PeopleSoft, WordPress, WSO2, Zimbra
- Exchange Server, Kiteworks, Gyazo
Primary pages named in those items:
- Cisco advisory cisco-sa-ISE-ABP-VNSW7Tn5, 16 September 2026
- Citrix bulletin CTX697096, 27 September 2026
- Arista Security Advisory 0183
- Check Point advisory, Fortinet PSIRT FG-IR-26-175
- CISA Known Exploited Vulnerabilities feed
- WordPress advisory GHSA-7hp8-65ch-5whp
- WSO2 advisory WSO2-2026-5328
- Zimbra 10.1.20 release post, JetBrains TeamCity advisory, CERT Polska on RouterOS
- Microsoft Security Response Center, CVE-2026-96940, Canadian Centre for Cyber Security alert AL26-023, DIVD case on Zammad, Helpfeel notice
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Network Security
- Threat Intelligence
- IT Security
- VPN
- United States of America
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.