Firewall and VPN patching: what to fix first
Your firewall, VPN and email gateway are the devices attackers now go for first, and in the past three months eight serious flaws in them have been actively exploited. Here is how to decide what gets patched today, what can wait, and what to ask your IT provider this week.
· 9 min read · Oramatel
If you run the firm
Why this lands on your desk
A firewall or VPN is the one device every attacker on the internet can reach. When a flaw in it is published, automated scanning usually starts within days, and a single unpatched box can hand over remote access to the whole office: client files, email and the accounts system.
The Essential Eight baseline, which insurers and larger clients increasingly ask about, expects these devices patched within two weeks, or within 48 hours when an exploit is circulating. You don't need to do it yourself. You do need to know it is being done.
Five questions to ask your IT provider this week
- Which of our devices face the internet — firewall, VPN, remote-access portal, email gateway — and what software version is each one running?
- Can the admin page of any of them be reached from the internet? It shouldn't be.
- Are any of them on the exploited list at the bottom of this page, and if so, when were they patched?
- Is anything past the vendor's end of support, so no fix will ever come?
- How quickly do you apply critical patches to these devices, and how would we know if one had already been broken into?
If the answers are vague, or nobody is sure, that is worth fixing before the next alert. The rest of this page is the detail your IT person can work from.
Triage order
Rank every device by exposure first, then by whether an exploit is known. Work down the list, and never let a lower tier delay a higher one. Management consoles come first: one compromise there hands over every device it manages.
| Tier | What it covers | Patch within |
|---|---|---|
| 1 | A management interface (firewall web UI, central manager, SD-WAN controller) reachable from the internet, with a known-exploited flaw | Same day. Cut internet access to it first |
| 2 | Any internet-facing device (VPN portal, firewall, mail gateway) with a flaw that is known-exploited or rated critical by the vendor | 48 hours |
| 3 | Internet-facing device, flaw rated non-critical by the vendor and no working exploit | 2 weeks |
| 4 | Network gear that isn't internet-facing, with management reachable only from an admin network | 1 month |
| 5 | End-of-life device with no fix coming | Replace it. Isolate it and restrict management until then |
Tiers 2 to 5 match the Essential Eight Maturity Level One patching rules for internet-facing and other network devices. Tier 1 is stricter on purpose. “Known-exploited” means listed in the CISA Known Exploited Vulnerabilities catalog or flagged as exploited in the vendor advisory. Not sure whether a device is past end of support? Check it here.
Per-device checklist
Run this for every firewall, VPN gateway and management console.
- Record vendor, model, software version and support end date
- Check whether the web UI, central manager or VPN portal is reachable from the internet. Test from outside, not by reading the config
- Match the version against the vendor advisories in the current alerts below
- Take a config backup and store it off the device
- Run the compromise checks below before patching, so evidence isn't lost in the upgrade
- Schedule the upgrade to the vendor's fixed release; for HA pairs, upgrade the standby first
- After the upgrade, confirm the running version and that VPN, routing and policies still work
- Rotate admin passwords, API keys and VPN pre-shared keys if the device was exposed while vulnerable
- Log the date, version and who did it in the change record
If you can't patch today
These cut exposure until the fix lands. They do not replace the patch.
- Remove internet access to management interfaces; allow them only from a named admin IP list or over VPN
- Turn off features you don't use, such as a clientless SSL VPN portal or web-based management on the WAN side
- Apply the vendor's published workaround or threat-prevention signature for the specific CVE, where one exists
- Require MFA on VPN and admin logins. It won't stop an authentication bypass, but it blocks credential reuse
- Geo-block VPN logins from countries you don't operate in
- Turn up logging on the device and forward it off-box, so an attack attempt is visible
Check for compromise
Patching closes the hole but does not remove an attacker who is already in. On any device that was exposed while vulnerable:
- Run the vendor's integrity or indicator-of-compromise check where one is published for the CVE
- Look for admin accounts, API keys or VPN users nobody recognises
- Compare the running config against the last known-good backup
- Review logs for logins from unfamiliar IPs and for the request patterns named in the advisory
- Check for unexpected outbound connections from the device itself
If you find signs of compromise, treat the device as untrusted. Rebuild it from a clean image, rotate every credential it held, and start your incident response. In Australia, report it to ASD through ReportCyber, and assess whether the Notifiable Data Breaches scheme applies.
Updated 6 October 2026
Current alerts: patch these first
Eight firewall, VPN and management flaws were confirmed exploited between July and early October 2026. Tier is from the triage order above.
Fixed versions were read from each vendor's advisory on 6 October 2026. Vendors revise them, and the Palo Alto list here is partial. Confirm the fixed release for your exact version in the linked advisory before you upgrade.
- Tier 1CVE-2026-20079 (CVSS 10.0)
Cisco Secure Firewall Management Center
- Attacker gets
- Root on the manager via its web UI, no login
- Exploitation
- Since Aug 2026; web shells deployed. CISA KEV 9 Sep
- Fix or action
- Upgrade to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 or 10.1.0 for your release line; no workaround exists. Block internet access to the FMC UI. To check for compromise, in expert mode run
zgrep "package_info.*license" /var/log/messages*and look for/var/tmp/license.tmp
- Tier 1CVE-2026-76504 (CVSS 9.8)
Cisco Catalyst SD-WAN Manager
- Attacker gets
- Admin API access, no login
- Exploitation
- Sep 2026. CISA KEV 30 Sep
- Fix or action
- Upgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1 for your release line; anything older than 20.9 must migrate. No workaround exists, so restrict access to trusted hosts. Then check logs for
j_security_checkfrom unknown IPs and users startingviptela-reserved-
- Tier 1CVE-2026-93616 (CVSS 9.8)
Check Point Management Server
- Attacker gets
- Run scripts on the server, no login
- Exploitation
- Targeted attacks since 23 Jul 2026
- Fix or action
- Apply the fix in sk1000171 (released 22 Sep). Affected: R82.20 without a Jumbo Hotfix; R82.10 Take 44 or below; R82 Take 126 or below; R81.20 Take 166 or below; R81.10 Take 190 or below. R81 and older are out of support: replace
- Tier 2CVE-2026-0257
Palo Alto GlobalProtect (PAN-OS, Prisma Access)
- Attacker gets
- A VPN session without credentials
- Exploitation
- Qilin ransomware affiliates since Jul 2026
- Fix or action
- Upgrade PAN-OS (e.g. 12.1.7+, 11.1.15+; check Palo Alto's advisory for your release line). Until then, disable Authentication Override on the portal
- Tier 2CVE-2026-104286 (CVSS 9.8)
Fortinet FortiMail
- Attacker gets
- Write arbitrary files on the appliance, no login
- Exploitation
- CISA KEV 1 Oct
- Fix or action
- Upgrade to 8.0.2, 7.6.7 or 7.4.9 or later; 7.2 has no fix, so move to 7.4. Until then, turn off the IBE service or block webmail from the internet. Check for connections to
79.141.169.187and45.129.0.192, and for an unexpected remote archive account
- Tier 2CVE-2026-85102
Check Point Security Gateway and Spark
- Attacker gets
- Code execution through a VPN certificate flaw, no login
- Exploitation
- Attempts since 12 Sep 2026
- Fix or action
- Apply the fix in sk1000117 (released 9 Sep); look for the certificate subject
CN=vpn,OU=users,O=global
- Tier 2CVE-2026-19490 (CVSS 9.3)
Citrix NetScaler ADC and Gateway
- Attacker gets
- Authentication bypass on gateway or AAA virtual servers
- Exploitation
- Attempts since 3 Sep 2026. CISA KEV 9 Sep
- Fix or action
- Upgrade to 14.1-73.32 or 13.1-63.21 or later (FIPS: 14.1-73.32 FIPS; 13.1 FIPS/NDcPP: 13.1-37.277); no workaround exists. Only exposed if configured as a Gateway or AAA virtual server; on 14.1-43.56+ and 13.1-61.28+, only with a SAML action
- Tier 2CVE-2025-25249 (CVSS 9.8 per NIST; Fortinet rates it High)
Fortinet FortiOS, FortiSwitchManager, FortiSASE
- Attacker gets
- Code execution, no login; used to plant the PivotC2 remote-access trojan
- Exploitation
- Since Jul 2026; 178 devices infected. CISA KEV 9 Sep
- Fix or action
- Upgrade FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 or later; 6.4 has no fix, so migrate. FortiSwitchManager: 7.2.7 or 7.0.6. Until then, remove
fabricfrom interface allowaccess, or block UDP 5246–5249 with a local-in policy
Not sure where your firm sits?
In a free 15-minute call we'll do a first-pass review of your edge devices: which ones are likely exposed to the internet, whether any match this list or are past end of support, and where to look first. A senior engineer, no sales pitch. If the box can't be patched at all, that is what our firewall end-of-life assessment is for.
Sources
- cisco-sa-onprem-fmc-authbypass-5JPp45V2: Secure FMC authentication bypass — Cisco
- cisco-sa-sdwan-webauth-xr8beuuU: Catalyst SD-WAN Manager API authentication bypass — Cisco
- CTX696939: NetScaler ADC and Gateway bulletin for CVE-2026-19489 and CVE-2026-19490 — Citrix
- FG-IR-25-084: FortiOS cw_acd heap overflow — Fortinet PSIRT
- FG-IR-26-175: FortiMail path traversal — Fortinet PSIRT
- CVE-2025-25249 — NVD
- CVE-2026-104286 — NVD
- CISA flags exploited Cisco, Citrix, Fortinet flaws — The Hacker News
- CISA adds exploited Cisco Catalyst SD-WAN Manager auth bypass to KEV — The Hacker News
- Check Point warns of management server zero-day — The Hacker News
- Critical vulnerability in Palo Alto GlobalProtect (CVE-2026-0257) — Beazley Security
- CISA adds Fortinet FortiMail 0-day to KEV — Cyber Security News
- Essential Eight maturity model — ASD
- Known Exploited Vulnerabilities Catalog — CISA
General information only, not advice for your specific environment. Product names belong to their vendors. Spotted something out of date? Tell us and we will fix it.