OramatelOramatel
Blog

Firewall and VPN patching: what to fix first

Your firewall, VPN and email gateway are the devices attackers now go for first, and in the past three months eight serious flaws in them have been actively exploited. Here is how to decide what gets patched today, what can wait, and what to ask your IT provider this week.

· 9 min read · Oramatel

If you run the firm

Why this lands on your desk

A firewall or VPN is the one device every attacker on the internet can reach. When a flaw in it is published, automated scanning usually starts within days, and a single unpatched box can hand over remote access to the whole office: client files, email and the accounts system.

The Essential Eight baseline, which insurers and larger clients increasingly ask about, expects these devices patched within two weeks, or within 48 hours when an exploit is circulating. You don't need to do it yourself. You do need to know it is being done.

Five questions to ask your IT provider this week

  1. Which of our devices face the internet — firewall, VPN, remote-access portal, email gateway — and what software version is each one running?
  2. Can the admin page of any of them be reached from the internet? It shouldn't be.
  3. Are any of them on the exploited list at the bottom of this page, and if so, when were they patched?
  4. Is anything past the vendor's end of support, so no fix will ever come?
  5. How quickly do you apply critical patches to these devices, and how would we know if one had already been broken into?

If the answers are vague, or nobody is sure, that is worth fixing before the next alert. The rest of this page is the detail your IT person can work from.

Triage order

Rank every device by exposure first, then by whether an exploit is known. Work down the list, and never let a lower tier delay a higher one. Management consoles come first: one compromise there hands over every device it manages.

TierWhat it coversPatch within
1A management interface (firewall web UI, central manager, SD-WAN controller) reachable from the internet, with a known-exploited flawSame day. Cut internet access to it first
2Any internet-facing device (VPN portal, firewall, mail gateway) with a flaw that is known-exploited or rated critical by the vendor48 hours
3Internet-facing device, flaw rated non-critical by the vendor and no working exploit2 weeks
4Network gear that isn't internet-facing, with management reachable only from an admin network1 month
5End-of-life device with no fix comingReplace it. Isolate it and restrict management until then

Tiers 2 to 5 match the Essential Eight Maturity Level One patching rules for internet-facing and other network devices. Tier 1 is stricter on purpose. “Known-exploited” means listed in the CISA Known Exploited Vulnerabilities catalog or flagged as exploited in the vendor advisory. Not sure whether a device is past end of support? Check it here.

Per-device checklist

Run this for every firewall, VPN gateway and management console.

  • Record vendor, model, software version and support end date
  • Check whether the web UI, central manager or VPN portal is reachable from the internet. Test from outside, not by reading the config
  • Match the version against the vendor advisories in the current alerts below
  • Take a config backup and store it off the device
  • Run the compromise checks below before patching, so evidence isn't lost in the upgrade
  • Schedule the upgrade to the vendor's fixed release; for HA pairs, upgrade the standby first
  • After the upgrade, confirm the running version and that VPN, routing and policies still work
  • Rotate admin passwords, API keys and VPN pre-shared keys if the device was exposed while vulnerable
  • Log the date, version and who did it in the change record

If you can't patch today

These cut exposure until the fix lands. They do not replace the patch.

  • Remove internet access to management interfaces; allow them only from a named admin IP list or over VPN
  • Turn off features you don't use, such as a clientless SSL VPN portal or web-based management on the WAN side
  • Apply the vendor's published workaround or threat-prevention signature for the specific CVE, where one exists
  • Require MFA on VPN and admin logins. It won't stop an authentication bypass, but it blocks credential reuse
  • Geo-block VPN logins from countries you don't operate in
  • Turn up logging on the device and forward it off-box, so an attack attempt is visible

Check for compromise

Patching closes the hole but does not remove an attacker who is already in. On any device that was exposed while vulnerable:

  • Run the vendor's integrity or indicator-of-compromise check where one is published for the CVE
  • Look for admin accounts, API keys or VPN users nobody recognises
  • Compare the running config against the last known-good backup
  • Review logs for logins from unfamiliar IPs and for the request patterns named in the advisory
  • Check for unexpected outbound connections from the device itself

If you find signs of compromise, treat the device as untrusted. Rebuild it from a clean image, rotate every credential it held, and start your incident response. In Australia, report it to ASD through ReportCyber, and assess whether the Notifiable Data Breaches scheme applies.

Updated 6 October 2026

Current alerts: patch these first

Eight firewall, VPN and management flaws were confirmed exploited between July and early October 2026. Tier is from the triage order above.

Fixed versions were read from each vendor's advisory on 6 October 2026. Vendors revise them, and the Palo Alto list here is partial. Confirm the fixed release for your exact version in the linked advisory before you upgrade.

  • Tier 1CVE-2026-20079 (CVSS 10.0)

    Cisco Secure Firewall Management Center

    Attacker gets
    Root on the manager via its web UI, no login
    Exploitation
    Since Aug 2026; web shells deployed. CISA KEV 9 Sep
    Fix or action
    Upgrade to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 or 10.1.0 for your release line; no workaround exists. Block internet access to the FMC UI. To check for compromise, in expert mode run zgrep "package_info.*license" /var/log/messages* and look for /var/tmp/license.tmp
  • Tier 1CVE-2026-76504 (CVSS 9.8)

    Cisco Catalyst SD-WAN Manager

    Attacker gets
    Admin API access, no login
    Exploitation
    Sep 2026. CISA KEV 30 Sep
    Fix or action
    Upgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1 for your release line; anything older than 20.9 must migrate. No workaround exists, so restrict access to trusted hosts. Then check logs for j_security_check from unknown IPs and users starting viptela-reserved-
  • Tier 1CVE-2026-93616 (CVSS 9.8)

    Check Point Management Server

    Attacker gets
    Run scripts on the server, no login
    Exploitation
    Targeted attacks since 23 Jul 2026
    Fix or action
    Apply the fix in sk1000171 (released 22 Sep). Affected: R82.20 without a Jumbo Hotfix; R82.10 Take 44 or below; R82 Take 126 or below; R81.20 Take 166 or below; R81.10 Take 190 or below. R81 and older are out of support: replace
  • Tier 2CVE-2026-0257

    Palo Alto GlobalProtect (PAN-OS, Prisma Access)

    Attacker gets
    A VPN session without credentials
    Exploitation
    Qilin ransomware affiliates since Jul 2026
    Fix or action
    Upgrade PAN-OS (e.g. 12.1.7+, 11.1.15+; check Palo Alto's advisory for your release line). Until then, disable Authentication Override on the portal
  • Tier 2CVE-2026-104286 (CVSS 9.8)

    Fortinet FortiMail

    Attacker gets
    Write arbitrary files on the appliance, no login
    Exploitation
    CISA KEV 1 Oct
    Fix or action
    Upgrade to 8.0.2, 7.6.7 or 7.4.9 or later; 7.2 has no fix, so move to 7.4. Until then, turn off the IBE service or block webmail from the internet. Check for connections to 79.141.169.187 and 45.129.0.192, and for an unexpected remote archive account
  • Tier 2CVE-2026-85102

    Check Point Security Gateway and Spark

    Attacker gets
    Code execution through a VPN certificate flaw, no login
    Exploitation
    Attempts since 12 Sep 2026
    Fix or action
    Apply the fix in sk1000117 (released 9 Sep); look for the certificate subject CN=vpn,OU=users,O=global
  • Tier 2CVE-2026-19490 (CVSS 9.3)

    Citrix NetScaler ADC and Gateway

    Attacker gets
    Authentication bypass on gateway or AAA virtual servers
    Exploitation
    Attempts since 3 Sep 2026. CISA KEV 9 Sep
    Fix or action
    Upgrade to 14.1-73.32 or 13.1-63.21 or later (FIPS: 14.1-73.32 FIPS; 13.1 FIPS/NDcPP: 13.1-37.277); no workaround exists. Only exposed if configured as a Gateway or AAA virtual server; on 14.1-43.56+ and 13.1-61.28+, only with a SAML action
  • Tier 2CVE-2025-25249 (CVSS 9.8 per NIST; Fortinet rates it High)

    Fortinet FortiOS, FortiSwitchManager, FortiSASE

    Attacker gets
    Code execution, no login; used to plant the PivotC2 remote-access trojan
    Exploitation
    Since Jul 2026; 178 devices infected. CISA KEV 9 Sep
    Fix or action
    Upgrade FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 or later; 6.4 has no fix, so migrate. FortiSwitchManager: 7.2.7 or 7.0.6. Until then, remove fabric from interface allowaccess, or block UDP 5246–5249 with a local-in policy

Not sure where your firm sits?

In a free 15-minute call we'll do a first-pass review of your edge devices: which ones are likely exposed to the internet, whether any match this list or are past end of support, and where to look first. A senior engineer, no sales pitch. If the box can't be patched at all, that is what our firewall end-of-life assessment is for.

Sources

General information only, not advice for your specific environment. Product names belong to their vendors. Spotted something out of date? Tell us and we will fix it.