TL;DR: State-sponsored and criminal groups are independently converging on the same edge vendors, with Tenable and SentinelOne’s joint analysis of 93 CVE-actor pairs showing 79% vendor-level overlap and 12 multi-nexus CVEs spanning China, Russia, DPRK, Iran, and ransomware actors, according to SentinelOne. The evidence shifts the problem from isolated CVEs to persistent vendor attack surfaces that outlast any single patch cycle.
NHIMG editorial — based on content published by SentinelOne: a joint Tenable-SentinelOne analysis of edge appliance exploitation and CVE-actor convergence
By the numbers:
- Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap.
- Citrix customers show a median of 461 days to patch, with 71% of affected environments still carrying unpatched Citrix CVEs after a full year.
Questions worth separating out
Q: How should security teams prioritise patching edge appliances with exposed CVEs?
A: Prioritise by privilege and reach, not just severity.
Q: Why do edge devices remain attractive after a CVE is disclosed?
A: They remain attractive because they sit in a high-trust position and are hard to patch quickly.
Q: What do teams get wrong about perimeter security in identity-heavy environments?
A: They assume the perimeter still decides trust, when in reality many attacks now begin with valid access and then move internally.
Practitioner guidance
- Map edge appliances to identity and secret ownership Inventory every credential, token, certificate, and directory binding stored on VPNs, firewalls, and remote-access appliances, then assign explicit owners for each secret path.
- Prioritise remediation by exposed network privilege Rank edge CVEs by administrative reach, authentication dependency, and lateral movement potential, not just by severity score or disclosure date.
- Remove long-lived secrets from appliance configuration Move LDAP binds, SSH keys, and admin credentials out of device configs and into managed secret systems with rotation and revocation controls.
What's in the full report
SentinelOne's full analysis covers the operational detail this post intentionally leaves for the source:
- Container-grain exposure methodology for comparing vendor attack surfaces across thousands of monitored environments
- Vendor-by-vendor remediation timing data, including the long tail of unpatched Citrix and Ivanti exposure
- The full CVE-actor attribution table with nexus categories and confidence tiers
- Incident-response examples showing how appliance-stored credentials were used after initial access
👉 Read SentinelOne's analysis of edge appliance exploitation and vendor convergence →
Edge appliance exploitation: what practitioners need to re-evaluate now?
Explore further
Vendor convergence is the real security signal. The most important finding is not that a single CVE was exploited, but that different actors independently return to the same vendor surfaces. That means defender attention should shift from one-off patch events to the repeatability of exposure across product lines. For practitioners, the question is whether their control model treats edge products as transient vulnerabilities or as durable attack surfaces.
A question worth separating out:
Q: Who is accountable when an edge appliance becomes an internal foothold?
A: Accountability usually spans network operations, IAM, and security leadership because the failure crosses device patching, secret governance, and access control. The organisation needs one owner for remediation timing and one owner for the credentials and trust relationships embedded in the appliance. Without that split of responsibility, exposure persists even after the CVE is known.
👉 Read our full editorial: Edge appliance exploitation is converging across state and criminal actors