Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices
Edge Infrastructure Under Siege (TL-2026-2153), also tracked as Edge Infrastructure Under Siege, is a high-severity tracked intrusion set, first published 2026-08-26. It is linked to a China, Russia, Iran, North Korea-nexus actor with medium confidence, affects SonicWall SMA1000 (Secure Mobile Access), references 12 CVEs (CVE-2026-15409, CVE-2023-42793, CVE-2024-3400), maps to 13 MITRE ATT&CK techniques (T1005, T1021, T1059), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2153
- Threat ID
- TL-2026-2153
- Also known as
- Edge Infrastructure Under Siege, Perimeter Device Exploitation Convergence
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-08-26
- Last reviewed
- 2026-08-26
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China, Russia, Iran, North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, finance, manufacturing, telecoms, research, managed service providers, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Edge Infrastructure Under Siege
Malware and tooling: GOREshell, INC Ransomware - S1139, ShadowPad, UPSTYLE, KNUCKLEBALL, ORANGETAIL, Operational Relay Box (ORB) network, ROOTRUN, Suo5
A joint Tenable Research Special Operations / SentinelOne Incident Readiness & Response analysis cross-references exposure telemetry (238 high-priority CVEs across thousands of customer containers) against 12 months of DFIR casework (66 CVEs) to build an 82-CVE, 93 CVE-actor-attribution-pair dataset spanning ~39 named threat actors. Datasets converge on 79% of the same vendor attack surfaces despite only 21% CVE-level overlap, and 12 CVEs show confirmed multi-nexus attribution where state-sponsored and financially motivated actors independently exploit the same edge-device vulnerability.
How Edge Infrastructure Under Siege works
Tenable Research Special Operations and SentinelOne Incident Readiness & Response combined two independently collected datasets — Tenable's exposure-management telemetry across thousands of customer containers and SentinelOne's 12-month DFIR casework spanning 66 CVEs — into an 82-distinct-CVE, 93-CVE-actor-attribution-pair corpus covering roughly 39 named threat actors across five nexus categories (China, Russia, Iran, DPRK, and financially motivated/ransomware). Despite only 21% CVE-level overlap between the two sources, the datasets converge on 79% of the same vendor attack surfaces, with full agreement on seven edge/remote-access vendors: Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware.
The report's core finding is convergent exploitation: 12 CVEs show confirmed multi-nexus attribution, where state-sponsored and financially motivated actors independently weaponize the same perimeter-device vulnerability rather than exclusively targeting it. Documented examples include CVE-2026-15409 (SonicWall SMA1000 SSRF), first exploited by the Volexity-tracked cluster UTA0533 for credential harvesting and subsequently weaponized en masse by INC Ransomware; CVE-2023-42793 (JetBrains TeamCity authentication bypass), independently exploited by Russia-nexus APT29/Cozy Bear and DPRK-nexus Lazarus Group; CVE-2024-3400 (PAN-OS GlobalProtect command injection), exploited as a zero-day by China-nexus UTA0218 to deploy the custom Python backdoor UPSTYLE and later reused by INC Ransomware; and CVE-2024-24919 (Check Point Quantum Gateway information disclosure), independently exploited by the China-nexus cluster PurpleHaze and the Iran-nexus, government-attributed actor Fox Kitten (Pioneer Kitten) to extract local-account password hashes for lateral movement.
Beyond the anchor CVEs, the corpus documents a Fortinet-specific chain: CVE-2024-47575 ("FortiJump," a missing-authentication flaw in the FGFM device-registration daemon fgfmsd) let an actor register an unauthorized device to a FortiManager instance, retrieve managed-device configurations and FortiOS256-hashed credentials, and remain undetected for roughly a month; and CVE-2025-59718/CVE-2026-24858, a SAML-signature-verification bypass in FortiCloud SSO that let attackers authenticate as legitimate SSO users and create rogue local administrator accounts on fully patched FortiGate firewalls, forcing Fortinet to ship a server-side (cloud-infrastructure) fix rather than a client patch. A parallel SonicWall GMS/Analytics chain (CVE-2023-34133 SQL injection, CVE-2023-34132 pass-the-hash, CVE-2023-34124 authentication bypass) let an actor create administrative accounts on a managed-service-provider console and pivot into multiple downstream customer environments, with resulting traffic assessed as click-fraud infrastructure abuse. A China-nexus actor separately chained the pre-disclosure Ivanti Cloud Services Appliance flaws CVE-2024-8963 (path traversal) and CVE-2024-8190 (OS command injection) to bypass admin authentication, execute code as root, and collect SSH keys and stored credentials for post-exploitation — later documented in the joint CISA/FBI advisory AA25-022A.
Exposure telemetry shows the highest container-level exposure on F5 (53.8% of monitored environments) and Citrix (28.8%), with Citrix also carrying the slowest remediation (461-day median time to patch; 71% of affected environments still unpatched after one year). High-priority CVEs across the combined Tenable list take a median of 146 days to remediate versus 122 days for lower-priority CVEs — a statistically significant 24-day gap — and only 54% of edge-device Known Exploited Vulnerabilities are fully remediated fleet-wide. Ivanti products show a structural "serial exploitation" pattern: EPMM averages roughly 8.5 months and Connect Secure roughly 13 months between successive exploited CVEs, which the report characterizes as a refreshing pipeline rather than isolated incidents. Actor density correlates with exposure: Fortinet (29 distinct actors across 5 nexus categories), Citrix (22 actors), and Ivanti (19 actors) are the most broadly targeted vendors in the corpus.
MITRE ATT&CK techniques used in TL-2026-2153
Collection
Lateral Movement
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
command-and-control
T1090.003 Proxy: Multi-hop Proxy
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1136.001 Create Account: Local Account; T1136.002 Create Account: Domain Account; T1505.003 Server Software Component: Web Shell
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys
credential-access
Affected products and versions in Edge Infrastructure Under Siege
- SonicWall — SMA1000 (Secure Mobile Access)
Vulnerable versions: pre-July 14, 2026 hotfix
Fixed in: July 14, 2026 hotfix release - SonicWall — Global Management System (GMS) / Analytics
Vulnerable versions: on-premise instances prior to July 2023 patch set
Fixed in: July 2023 SonicWall GMS/Analytics patch set - JetBrains — TeamCity Server (on-premise)
Vulnerable versions: prior to 2023.05.4
Fixed in: 2023.05.4 and later - Palo Alto Networks — PAN-OS GlobalProtect gateway/portal
Vulnerable versions: 10.2; 11.0; 11.1 (with GlobalProtect gateway/portal + device telemetry enabled)
Fixed in: vendor hotfixes per security.paloaltonetworks.com/CVE-2024-3400 - Check Point — Quantum Security Gateway / CloudGuard Network / Quantum Maestro / Quantum Scalable Chassis / Quantum Spark
Vulnerable versions: gateways configured with IPSec VPN, remote access VPN, or Mobile Access blade prior to hotfix
Fixed in: R81.20, R81.10, R81, R80.40 (Security Gateway/CloudGuard); R81.20/R81.10/R80.40/R80.30SP/R80.20SP (Maestro/Scalable Chassis); R81.10.x/R80.20.x/R77.20.x (Quantum Spark), per sk182336 - Fortinet — FortiManager (fgfmsd / FGFM device registration)
Vulnerable versions: versions affected by FG-IR-24-423 prior to fix
Fixed in: Fortinet FG-IR-24-423 fixed releases - Fortinet — FortiCloud SSO (backing FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb)
Vulnerable versions: all tenants prior to server-side patch
Fixed in: Fortinet cloud-side patch deployed January 26, 2026 - Ivanti — Cloud Services Appliance (CSA)
Vulnerable versions: prior to 4.6 Patch 519
Fixed in: 4.6 Patch 519 and later
Remediation for Edge Infrastructure Under Siege
Patches
- Ivanti Cloud Services Appliance 4.6 Patch 519 or later (CVE-2024-8963, CVE-2024-8190)
- JetBrains TeamCity 2023.05.4 or later (CVE-2023-42793)
- PAN-OS fixed releases across the 10.2/11.0/11.1 branches (CVE-2024-3400)
- Check Point Security Gateway R81.20/R81.10/R81/R80.40 (and corresponding Maestro/Scalable Chassis/Quantum Spark releases) hotfix per sk182336 (CVE-2024-24919)
- SonicWall SMA1000 hotfix released July 14, 2026 (CVE-2026-15409, CVE-2026-15410)
- SonicWall GMS/Analytics July 2023 patch set (CVE-2023-34133, CVE-2023-34132, CVE-2023-34124)
- FortiManager fix for CVE-2024-47575 (FG-IR-24-423) plus fgfm-deny-unknown enforcement
Immediate actions
- Patch F5 and Citrix edge devices first — highest container-level exposure in the dataset (53.8% and 28.8% respectively) combined with the slowest observed remediation (461-day median for Citrix, 71% still unpatched after one year)
- Apply the SonicWall SMA1000 July 14, 2026 hotfix for CVE-2026-15409/CVE-2026-15410 and rotate all credentials stored on internet-facing appliances that were exposed before the fix
- Enable fgfm-deny-unknown on FortiManager to block unauthorized FGFM device registration abused via CVE-2024-47575 (FortiJump)
- Confirm FortiCloud SSO SAML signature verification is enforced following Fortinet's January 26, 2026 server-side patch for CVE-2025-59718/CVE-2026-24858, and audit FortiGate/FortiManager/FortiAnalyzer/FortiProxy/FortiWeb for unexpected local admin accounts created via SSO
Workarounds
- Disable internet-facing management interfaces on edge appliances where immediate patching is not possible
- Enforce certificate validation and deny-unknown policies on FortiGate-to-FortiManager (FGFM) registration to prevent rogue-device onboarding
- Minimize enabled feature sets on perimeter devices and run endpoint protection in protect mode for defense-in-depth, per the joint Tenable/SentinelOne recommendation
Longer-term hardening
- Implement edge-device-specific patch SLAs shorter than the organizational default — the combined dataset shows a 122-146 day median remediation window for high-priority CVEs, well past the observed exploitation windows
- Audit Ivanti Connect Secure and EPMM deployments and budget for a new exploitable CVE within the observed 8.5-13 month serial-exploitation interval on those product lines
- Treat edge exposure as a cross-signal prioritization input (attribution + severity + exposure volume) rather than relying on CVSS score alone, given 79% vendor-surface convergence despite only 21% CVE-level overlap between independent telemetry and DFIR sources
CVEs associated with Edge Infrastructure Under Siege
CVE-2026-15409, CVE-2023-42793, CVE-2024-3400, CVE-2024-24919, CVE-2025-59718, CVE-2026-24858, CVE-2024-47575, CVE-2023-34133, CVE-2023-34132, CVE-2023-34124, CVE-2024-8963, CVE-2024-8190
Weaknesses (CWE) in Edge Infrastructure Under Siege
CWE-918, CWE-78, CWE-306, CWE-89, CWE-287, CWE-347, CWE-200, CWE-22
Timeline of Edge Infrastructure Under Siege
- SonicWall publishes an urgent security advisory for 15 GMS/Analytics vulnerabilities, including CVE-2023-34133 (SQL injection), CVE-2023-34132 (pass-the-hash), and CVE-2023-34124 (authentication bypass).
- CVE-2023-42793 (JetBrains TeamCity authentication bypass) confirmed under active exploitation; CISA lists it as known exploited, with CISA later attributing exploitation to Russia-nexus APT29/Cozy Bear.
- China-nexus actor UTA0218 begins exploiting CVE-2024-3400 as a zero-day against PAN-OS GlobalProtect firewalls, per Volexity.
- Check Point observes the earliest exploitation attempts against CVE-2024-24919 (Quantum Gateway information disclosure).
- CISA publishes guidance and adds CVE-2024-3400 to the Known Exploited Vulnerabilities catalog.
- In-the-wild exploitation of CVE-2024-24919 escalates, with actors enumerating and extracting local-account password hashes, including Active Directory bind credentials.
- Check Point publishes its zero-day advisory for CVE-2024-24919 and ships hotfixes across Quantum/CloudGuard product lines.
- A China-nexus actor chains pre-disclosure Ivanti CSA vulnerabilities CVE-2024-8963 and CVE-2024-8190 to bypass authentication, gain root code execution, and collect SSH keys and stored credentials.
- FortiManager instances are exploited in the wild via CVE-2024-47575 ("FortiJump"); one documented actor registers a rogue device and remains present for roughly a month before detection.
- CISA and the FBI publish joint advisory AA25-022A on the Ivanti CSA exploit chains (CVE-2024-8963/CVE-2024-9379/CVE-2024-8190/CVE-2024-9380).
- Multiple Fortinet customers report attackers creating new local administrator accounts on fully patched FortiGate firewalls, the first observable symptom of the CVE-2026-24858 FortiCloud SSO bypass.
- Fortinet deploys a server-side patch to FortiCloud SSO infrastructure remediating CVE-2025-59718/CVE-2025-59719.
- Fortinet discloses CVE-2026-24858 as a net-new FortiCloud SSO authentication-bypass vulnerability under active zero-day exploitation; CISA adds it to the KEV catalog the same window.
- Volexity-tracked actor UTA0533 begins exploiting SonicWall SMA1000 zero-days (later CVE-2026-15409/CVE-2026-15410) roughly three weeks before SonicWall's hotfix.
- Tenable Research Special Operations and SentinelOne Incident Readiness & Response publish the combined 82-CVE, 93-attribution-pair "Edge Infrastructure Under Siege" analysis.
Sources cited for Edge Infrastructure Under Siege
- Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who's Exploiting Your Perimeter
- SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited
- Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858
- Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications (AA25-022A)
- Palo Alto Networks Releases Guidance for Vulnerability in PAN-OS, CVE-2024-3400
- Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
- From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
- sk182336 - Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure
- Analysis of Single Sign-On Abuse on FortiOS
- Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
- CVE-2024-47575: FortiManager Missing Authentication Zero-Day Vulnerability Explained
- Technical Advisory – SonicWall Global Management System (GMS) & Analytics – Multiple Critical Vulnerabilities
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- CVE-2023-42793: CozyBear Targets Software Developers Exploiting JetBrains TeamCity
More in threat intel
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and Scope Violations Found in Safety Testing
Detection coverage for TL-2026-2153
As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2153 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.