Edge Infrastructure Under Siege: State Actors and Cybercriminals Converge on Shared Vulnerabilities
A joint Tenable-SentinelOne analysis reveals that both state-sponsored actors and cybercriminals are independently exploiting the same edge infrastructure vulnerabilities, targeting the same products and vendors.

A comprehensive analysis by Tenable and SentinelOne, examining 93 CVE-to-actor attribution pairs, has uncovered a significant trend: the convergence of both state-sponsored threat actors and financially motivated cybercriminals on the same edge infrastructure vulnerabilities. This joint effort, drawing on Tenable's exposure telemetry and SentinelOne's incident response casework, indicates that the shared attack surface of network edge devices is a prime target for diverse adversary groups, challenging the notion that these exploits are solely the domain of nation-states.
The analysis highlights that while headlines often focus on specific nation-state campaigns, the reality is a broader exploitation landscape. Twelve specific CVEs within the combined dataset demonstrated multi-nexus attribution, meaning actors from China, Russia, North Korea, and Iran, alongside ransomware groups, were found to be independently exploiting the identical vulnerability. This shared exploitation pattern underscores a structural issue where the same entry points are leveraged by different categories of adversaries, often with different objectives, from espionage to financial gain.
Contrary to popular perception, vendors like Fortinet, frequently associated with edge device attacks in public discourse, are not the sole focus. Tenable's data shows F5 products exhibiting the highest exposure rate at 54%, with Citrix products demonstrating the slowest remediation patterns, averaging 461 days to patch. This indicates that while certain vendors are heavily targeted, the overall exposure across various edge device manufacturers remains a critical concern, with patching complexities contributing to prolonged windows of vulnerability.
Remediation complexity, particularly for high-priority vulnerabilities, is identified as a significant factor contributing to extended exploitation periods. The study found a statistically significant 24-day gap in remediation time for high-priority CVEs compared to all other vulnerabilities. This delay is attributed to the operational challenges of patching edge devices, such as the need for downtime, complex change management processes, and the lack of standardized patching workflows common to endpoint devices.
The serial exploitation of specific product lines, such as Ivanti EPMM and Ivanti Connect Secure, further emphasizes the persistent nature of these attacks. These products experience a new exploited CVE approximately every 8.5 to 13 months, indicating a continuous pipeline of vulnerability discovery and exploitation targeting the same infrastructure. This pattern suggests that patching a single vulnerability does not eliminate the vendor's attack surface from the threat landscape.
The report stresses the importance of adopting multiple defense-in-depth strategies. While rapid patching remains crucial, organizations are also advised to minimize their attack surface through feature-set minimization and to implement endpoint protection in 'protect mode' to better thwart lateral movement once initial access is gained. The convergence of threat actors on shared vulnerabilities necessitates a holistic security approach that accounts for the diverse motivations and capabilities of adversaries.
Ultimately, the findings underscore that state-sponsored and ransomware actors are not operating in isolated ecosystems. They structurally converge on the same vendor attack surfaces, making it imperative for organizations to defend against all actor categories simultaneously. An organization that focuses its defenses solely on nation-state tactics, techniques, and procedures (TTPs) may remain vulnerable to ransomware operators exploiting the same weaknesses, and vice versa.
This new analysis from SentinelOne Labs, in conjunction with Tenable, provides further depth by examining 93 CVE-actor attribution pairs. It highlights that twelve specific CVEs have been independently exploited by both state-sponsored actors and cybercriminals, underscoring a shared exploitation landscape. The research also reveals that vendors like F5 and Citrix face significant exposure and slow remediation, with Ivanti products experiencing repeated exploitation of new vulnerabilities.