Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .
In the same week, two warnings aimed at the same kind of equipment. On October 6, the FBI and Secret Service said the FortiBleed campaign against Fortinet firewalls and VPN gateways is still active and has been used as an entry point for ransomware. Two days earlier, Citrix patched a NetScaler flaw that attackers were already exploiting, and the U.S. cybersecurity agency CISA added it to its list of actively exploited vulnerabilities. Neither story is about a consumer VPN app. Both are about the gateway that a business puts on the edge of its network, and they explain a trend that is now showing up in the biggest breach datasets of the year.
What the 2026 Data Says
The Verizon 2026 Data Breach Investigations Report analyzed more than 31,000 incidents, including more than 22,000 confirmed breaches in 145 countries. Its headline finding: exploitation of vulnerabilities is now the most common way attackers get in, at 31% of breaches. Credential abuse, the previous leader, fell to 13%. Ransomware grew to 48% of all breaches, up from 44%.
The patching picture is worse. Only 26% of the most critical vulnerabilities, the ones on CISA's Known Exploited Vulnerabilities list, were fully fixed in 2025, down from 38% the year before, and the median time to fix rose from 32 to 43 days. For small and medium businesses, Verizon lists exploitation of vulnerabilities (26%), credential abuse (13%), and phishing (9%) as the top ways in.
Push Security's review of the report adds the detail that matters most here: edge devices and VPNs accounted for 22% of vulnerability-exploitation breaches, up from 3% the year before. That figure comes from the review rather than Verizon's summary, so treat it as secondary.
Google's Mandiant M-Trends 2026 points the same way. Exploits were the most common initial infection vector for the sixth year in a row, at 32% of investigations. Mandiant also reports that some attackers stay hidden longer by persisting on edge devices "that typically lack standard telemetry," and says the mean time to exploit has dropped so far that attackers are compromising edge and core network devices before vendors release a patch.
Case 1: FortiBleed Is About Passwords, Not a Bug
FortiBleed surfaced in June. BleepingComputer reported that an exposed server held apparently valid VPN credentials for 73,932 firewall addresses in 194 countries, according to Hudson Rock's analysis. Fortinet's own response was blunt: "This is not a new Fortinet vulnerability." Its analysis points to reused credentials from earlier incidents and brute-force attempts against devices with weak password habits and no multi-factor authentication.
Later research widened the picture. As BleepingComputer reported in July, SOCRadar found more than 430,000 FortiGate firewalls were targeted and linked the operation to members of the INC and Lynx ransomware groups. On October 6, CyberScoop reported the FBI and Secret Service alert, which says affected organizations "may find themselves locked out of their systems" if attackers disable accounts or change passwords, and that FortiBleed "has been observed as an initial entry point for ransomware affiliates."
The agencies' advice is practical: restrict or remove internet-facing administration, reset credentials, turn on multi-factor authentication, and review firewall and VPN users and logs for changes you did not make.
Credential leaks start most of these stories. CyberFence encrypts your connection with AES-256-GCM, blocks known-bad domains with Web Shield, and runs a zero-logs policy, from $7.99/mo.
See CyberFence Plans →What Happens After the Gateway Falls
The Register's account of the advisory says attackers create accounts that were not on the device and, in some cases, delete existing accounts to block owners from getting back in while they try to move deeper into the network. The advisory ties the access to ransomware affiliates, naming INC/Lynx and Payload. The Register adds that SOCRadar said in July it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed.
That is the real danger of a compromised gateway. It is not the device itself, it is the way in to everything behind it. The agencies also warn against paying ransoms and ask victims to report incidents so others can be warned.
Case 2: A NetScaler Zero-Day Exploited Within Days
The second story is the opposite kind of failure: a real software flaw. BleepingComputer reports that Citrix released emergency updates on October 4 for CVE-2026-88779, a memory flaw in NetScaler ADC and NetScaler Gateway appliances configured for SAML authentication. Citrix describes it as a denial-of-service issue, and said it saw targeted attacks against unmitigated systems. CISA added it to its exploited-vulnerabilities catalog with a deadline of October 7 for federal agencies. Researchers are looking into whether it can also be used to run code, but Citrix has not confirmed that.
Citrix also warned that systems already updated for a group of earlier NetScaler flaws, CVE-2026-88771 through CVE-2026-88778, may need to be updated again. For a small IT team, that is the daily reality of running a gateway: patches arrive back to back.
Why Gateways Are Such Good Targets
- They face the internet by design. A gateway has to accept connections from outside, so anyone can find it and try it.
- They hold the keys. VPN credentials and admin accounts on these devices can open the door to the whole network behind them. FortiBleed attackers created new admin accounts and, in some cases, locked owners out.
- They are hard to watch. Mandiant notes that edge appliances cannot run standard endpoint detection software, so intrusions can go unseen for long periods.
- They are slow to patch. A 43-day median fix time is a long window when exploitation can begin before a patch exists.
A Checklist for Small Businesses
If your business runs its own firewall or VPN appliance, or a provider runs one for you, ask these questions this week:
- Is the management page reachable from the internet? If it does not have to be, close it. This was the first step in the FBI and Secret Service guidance.
- Does every admin and VPN account use multi-factor authentication and a unique password? Reused passwords were the engine of FortiBleed. See how credential stuffing works.
- How fast do you patch appliances on CISA's exploited list? Aim for days, not weeks.
- Do you review accounts and logs? Look for administrators or VPN users you did not create.
- Can you retire what you cannot maintain? An unpatched appliance is a liability, not a protection.
Where a Managed VPN Fits, and Where It Does Not
Be clear about the limits. CyberFence is not a firewall, it does not patch or protect your Fortinet or Citrix devices, and it is not a replacement if you need staff to reach servers inside your office network. For that, you still need a properly maintained gateway or a modern access service. Our guides on VPNs versus firewalls and zero trust versus VPN explain the options.
Many small businesses, though, run a VPN for a simpler reason: keeping staff safe on hotel, airport, café, and home networks. For that job, a managed service changes the risk. Each device connects outward to the provider, so there is no gateway on your network for attackers to scan, no admin page for you to expose, and no appliance for you to patch. The provider's team handles the infrastructure for every customer at once. The tradeoff is trust: you are relying on the provider, which is why a US-operated, zero-logs service with published compliance matters. Hosted services can be attacked too, as we cover in Can a VPN Be Hacked?
CyberFence Teams is built for that use. It starts at $12 per seat per month with a two-seat minimum and no contracts. The admin dashboard shows who is actually connected, with adoption alerts and device visibility, and compliance reports are included. Every Teams seat also includes Breach Monitor, which matters because FortiBleed began with leaked credentials: when an employee's email shows up in a new leak, you can force a password change before it is used. For individuals, Breach Monitor is a separate product, as explained in What Is a Breach Monitor? You can compare options for staff on the Teams page, or read about VPNs for small business remote teams.
The Bottom Line
The trend is clear and well documented: attackers go where the exposed, unwatched, slow-to-patch systems are, and for many organizations that is the VPN or firewall appliance at the edge. You cannot make that risk disappear, but you can shrink it. Close what does not need to be open, use unique passwords with multi-factor authentication, patch known-exploited flaws quickly, and avoid running infrastructure you cannot keep up to date. For protecting people on untrusted networks, a managed, no-logs VPN keeps that job off your own hardware.
Protect people, not just the perimeter. One CyberFence subscription covers your devices with an AES-256-GCM encrypted tunnel, Web Shield DNS blocking, and zero logs, with nothing for you to host or patch.
Get Protected →Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .