Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices

Edge Infrastructure Under Siege (TL-2026-2153), also tracked as Edge Infrastructure Under Siege, is a high-severity tracked intrusion set, first published 2026-08-26. It is linked to a China, Russia, Iran, North Korea-nexus actor with medium confidence, affects SonicWall SMA1000 (Secure Mobile Access), references 12 CVEs (CVE-2026-15409, CVE-2023-42793, CVE-2024-3400), maps to 13 MITRE ATT&CK techniques (T1005, T1021, T1059), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2153

Threat ID
TL-2026-2153
Also known as
Edge Infrastructure Under Siege, Perimeter Device Exploitation Convergence
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-26
Last reviewed
2026-08-26
Attribution confidence
MEDIUM
Nation-state nexus
China, Russia, Iran, North Korea
Motivation
ESPIONAGE
Target sectors
government administration, finance, manufacturing, telecoms, research, managed service providers, technology
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Edge Infrastructure Under Siege

Malware and tooling: GOREshell, INC Ransomware - S1139, ShadowPad, UPSTYLE, KNUCKLEBALL, ORANGETAIL, Operational Relay Box (ORB) network, ROOTRUN, Suo5

A joint Tenable Research Special Operations / SentinelOne Incident Readiness & Response analysis cross-references exposure telemetry (238 high-priority CVEs across thousands of customer containers) against 12 months of DFIR casework (66 CVEs) to build an 82-CVE, 93 CVE-actor-attribution-pair dataset spanning ~39 named threat actors. Datasets converge on 79% of the same vendor attack surfaces despite only 21% CVE-level overlap, and 12 CVEs show confirmed multi-nexus attribution where state-sponsored and financially motivated actors independently exploit the same edge-device vulnerability.

How Edge Infrastructure Under Siege works

Tenable Research Special Operations and SentinelOne Incident Readiness & Response combined two independently collected datasets — Tenable's exposure-management telemetry across thousands of customer containers and SentinelOne's 12-month DFIR casework spanning 66 CVEs — into an 82-distinct-CVE, 93-CVE-actor-attribution-pair corpus covering roughly 39 named threat actors across five nexus categories (China, Russia, Iran, DPRK, and financially motivated/ransomware). Despite only 21% CVE-level overlap between the two sources, the datasets converge on 79% of the same vendor attack surfaces, with full agreement on seven edge/remote-access vendors: Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware.

The report's core finding is convergent exploitation: 12 CVEs show confirmed multi-nexus attribution, where state-sponsored and financially motivated actors independently weaponize the same perimeter-device vulnerability rather than exclusively targeting it. Documented examples include CVE-2026-15409 (SonicWall SMA1000 SSRF), first exploited by the Volexity-tracked cluster UTA0533 for credential harvesting and subsequently weaponized en masse by INC Ransomware; CVE-2023-42793 (JetBrains TeamCity authentication bypass), independently exploited by Russia-nexus APT29/Cozy Bear and DPRK-nexus Lazarus Group; CVE-2024-3400 (PAN-OS GlobalProtect command injection), exploited as a zero-day by China-nexus UTA0218 to deploy the custom Python backdoor UPSTYLE and later reused by INC Ransomware; and CVE-2024-24919 (Check Point Quantum Gateway information disclosure), independently exploited by the China-nexus cluster PurpleHaze and the Iran-nexus, government-attributed actor Fox Kitten (Pioneer Kitten) to extract local-account password hashes for lateral movement.

Beyond the anchor CVEs, the corpus documents a Fortinet-specific chain: CVE-2024-47575 ("FortiJump," a missing-authentication flaw in the FGFM device-registration daemon fgfmsd) let an actor register an unauthorized device to a FortiManager instance, retrieve managed-device configurations and FortiOS256-hashed credentials, and remain undetected for roughly a month; and CVE-2025-59718/CVE-2026-24858, a SAML-signature-verification bypass in FortiCloud SSO that let attackers authenticate as legitimate SSO users and create rogue local administrator accounts on fully patched FortiGate firewalls, forcing Fortinet to ship a server-side (cloud-infrastructure) fix rather than a client patch. A parallel SonicWall GMS/Analytics chain (CVE-2023-34133 SQL injection, CVE-2023-34132 pass-the-hash, CVE-2023-34124 authentication bypass) let an actor create administrative accounts on a managed-service-provider console and pivot into multiple downstream customer environments, with resulting traffic assessed as click-fraud infrastructure abuse. A China-nexus actor separately chained the pre-disclosure Ivanti Cloud Services Appliance flaws CVE-2024-8963 (path traversal) and CVE-2024-8190 (OS command injection) to bypass admin authentication, execute code as root, and collect SSH keys and stored credentials for post-exploitation — later documented in the joint CISA/FBI advisory AA25-022A.

Exposure telemetry shows the highest container-level exposure on F5 (53.8% of monitored environments) and Citrix (28.8%), with Citrix also carrying the slowest remediation (461-day median time to patch; 71% of affected environments still unpatched after one year). High-priority CVEs across the combined Tenable list take a median of 146 days to remediate versus 122 days for lower-priority CVEs — a statistically significant 24-day gap — and only 54% of edge-device Known Exploited Vulnerabilities are fully remediated fleet-wide. Ivanti products show a structural "serial exploitation" pattern: EPMM averages roughly 8.5 months and Connect Secure roughly 13 months between successive exploited CVEs, which the report characterizes as a refreshing pipeline rather than isolated incidents. Actor density correlates with exposure: Fortinet (29 distinct actors across 5 nexus categories), Citrix (22 actors), and Ivanti (19 actors) are the most broadly targeted vendors in the corpus.

MITRE ATT&CK techniques used in TL-2026-2153

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

command-and-control

T1090.003 Proxy: Multi-hop Proxy

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1136.001 Create Account: Local Account; T1136.002 Create Account: Domain Account; T1505.003 Server Software Component: Web Shell

Credential Access

T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys

credential-access

T1606.002 Forge Web Credentials: SAML Tokens

Affected products and versions in Edge Infrastructure Under Siege

  • SonicWall — SMA1000 (Secure Mobile Access)
    Vulnerable versions: pre-July 14, 2026 hotfix
    Fixed in: July 14, 2026 hotfix release
  • SonicWall — Global Management System (GMS) / Analytics
    Vulnerable versions: on-premise instances prior to July 2023 patch set
    Fixed in: July 2023 SonicWall GMS/Analytics patch set
  • JetBrains — TeamCity Server (on-premise)
    Vulnerable versions: prior to 2023.05.4
    Fixed in: 2023.05.4 and later
  • Palo Alto Networks — PAN-OS GlobalProtect gateway/portal
    Vulnerable versions: 10.2; 11.0; 11.1 (with GlobalProtect gateway/portal + device telemetry enabled)
    Fixed in: vendor hotfixes per security.paloaltonetworks.com/CVE-2024-3400
  • Check Point — Quantum Security Gateway / CloudGuard Network / Quantum Maestro / Quantum Scalable Chassis / Quantum Spark
    Vulnerable versions: gateways configured with IPSec VPN, remote access VPN, or Mobile Access blade prior to hotfix
    Fixed in: R81.20, R81.10, R81, R80.40 (Security Gateway/CloudGuard); R81.20/R81.10/R80.40/R80.30SP/R80.20SP (Maestro/Scalable Chassis); R81.10.x/R80.20.x/R77.20.x (Quantum Spark), per sk182336
  • Fortinet — FortiManager (fgfmsd / FGFM device registration)
    Vulnerable versions: versions affected by FG-IR-24-423 prior to fix
    Fixed in: Fortinet FG-IR-24-423 fixed releases
  • Fortinet — FortiCloud SSO (backing FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb)
    Vulnerable versions: all tenants prior to server-side patch
    Fixed in: Fortinet cloud-side patch deployed January 26, 2026
  • Ivanti — Cloud Services Appliance (CSA)
    Vulnerable versions: prior to 4.6 Patch 519
    Fixed in: 4.6 Patch 519 and later

Remediation for Edge Infrastructure Under Siege

Patches

  • Ivanti Cloud Services Appliance 4.6 Patch 519 or later (CVE-2024-8963, CVE-2024-8190)
  • JetBrains TeamCity 2023.05.4 or later (CVE-2023-42793)
  • PAN-OS fixed releases across the 10.2/11.0/11.1 branches (CVE-2024-3400)
  • Check Point Security Gateway R81.20/R81.10/R81/R80.40 (and corresponding Maestro/Scalable Chassis/Quantum Spark releases) hotfix per sk182336 (CVE-2024-24919)
  • SonicWall SMA1000 hotfix released July 14, 2026 (CVE-2026-15409, CVE-2026-15410)
  • SonicWall GMS/Analytics July 2023 patch set (CVE-2023-34133, CVE-2023-34132, CVE-2023-34124)
  • FortiManager fix for CVE-2024-47575 (FG-IR-24-423) plus fgfm-deny-unknown enforcement

Immediate actions

  • Patch F5 and Citrix edge devices first — highest container-level exposure in the dataset (53.8% and 28.8% respectively) combined with the slowest observed remediation (461-day median for Citrix, 71% still unpatched after one year)
  • Apply the SonicWall SMA1000 July 14, 2026 hotfix for CVE-2026-15409/CVE-2026-15410 and rotate all credentials stored on internet-facing appliances that were exposed before the fix
  • Enable fgfm-deny-unknown on FortiManager to block unauthorized FGFM device registration abused via CVE-2024-47575 (FortiJump)
  • Confirm FortiCloud SSO SAML signature verification is enforced following Fortinet's January 26, 2026 server-side patch for CVE-2025-59718/CVE-2026-24858, and audit FortiGate/FortiManager/FortiAnalyzer/FortiProxy/FortiWeb for unexpected local admin accounts created via SSO

Workarounds

  • Disable internet-facing management interfaces on edge appliances where immediate patching is not possible
  • Enforce certificate validation and deny-unknown policies on FortiGate-to-FortiManager (FGFM) registration to prevent rogue-device onboarding
  • Minimize enabled feature sets on perimeter devices and run endpoint protection in protect mode for defense-in-depth, per the joint Tenable/SentinelOne recommendation

Longer-term hardening

  • Implement edge-device-specific patch SLAs shorter than the organizational default — the combined dataset shows a 122-146 day median remediation window for high-priority CVEs, well past the observed exploitation windows
  • Audit Ivanti Connect Secure and EPMM deployments and budget for a new exploitable CVE within the observed 8.5-13 month serial-exploitation interval on those product lines
  • Treat edge exposure as a cross-signal prioritization input (attribution + severity + exposure volume) rather than relying on CVSS score alone, given 79% vendor-surface convergence despite only 21% CVE-level overlap between independent telemetry and DFIR sources

CVEs associated with Edge Infrastructure Under Siege

CVE-2026-15409, CVE-2023-42793, CVE-2024-3400, CVE-2024-24919, CVE-2025-59718, CVE-2026-24858, CVE-2024-47575, CVE-2023-34133, CVE-2023-34132, CVE-2023-34124, CVE-2024-8963, CVE-2024-8190

Weaknesses (CWE) in Edge Infrastructure Under Siege

CWE-918, CWE-78, CWE-306, CWE-89, CWE-287, CWE-347, CWE-200, CWE-22

Timeline of Edge Infrastructure Under Siege

  • SonicWall publishes an urgent security advisory for 15 GMS/Analytics vulnerabilities, including CVE-2023-34133 (SQL injection), CVE-2023-34132 (pass-the-hash), and CVE-2023-34124 (authentication bypass).
  • CVE-2023-42793 (JetBrains TeamCity authentication bypass) confirmed under active exploitation; CISA lists it as known exploited, with CISA later attributing exploitation to Russia-nexus APT29/Cozy Bear.
  • China-nexus actor UTA0218 begins exploiting CVE-2024-3400 as a zero-day against PAN-OS GlobalProtect firewalls, per Volexity.
  • Check Point observes the earliest exploitation attempts against CVE-2024-24919 (Quantum Gateway information disclosure).
  • CISA publishes guidance and adds CVE-2024-3400 to the Known Exploited Vulnerabilities catalog.
  • In-the-wild exploitation of CVE-2024-24919 escalates, with actors enumerating and extracting local-account password hashes, including Active Directory bind credentials.
  • Check Point publishes its zero-day advisory for CVE-2024-24919 and ships hotfixes across Quantum/CloudGuard product lines.
  • A China-nexus actor chains pre-disclosure Ivanti CSA vulnerabilities CVE-2024-8963 and CVE-2024-8190 to bypass authentication, gain root code execution, and collect SSH keys and stored credentials.
  • FortiManager instances are exploited in the wild via CVE-2024-47575 ("FortiJump"); one documented actor registers a rogue device and remains present for roughly a month before detection.
  • CISA and the FBI publish joint advisory AA25-022A on the Ivanti CSA exploit chains (CVE-2024-8963/CVE-2024-9379/CVE-2024-8190/CVE-2024-9380).
  • Multiple Fortinet customers report attackers creating new local administrator accounts on fully patched FortiGate firewalls, the first observable symptom of the CVE-2026-24858 FortiCloud SSO bypass.
  • Fortinet deploys a server-side patch to FortiCloud SSO infrastructure remediating CVE-2025-59718/CVE-2025-59719.
  • Fortinet discloses CVE-2026-24858 as a net-new FortiCloud SSO authentication-bypass vulnerability under active zero-day exploitation; CISA adds it to the KEV catalog the same window.
  • Volexity-tracked actor UTA0533 begins exploiting SonicWall SMA1000 zero-days (later CVE-2026-15409/CVE-2026-15410) roughly three weeks before SonicWall's hotfix.
  • Tenable Research Special Operations and SentinelOne Incident Readiness & Response publish the combined 82-CVE, 93-attribution-pair "Edge Infrastructure Under Siege" analysis.

Sources cited for Edge Infrastructure Under Siege

More in threat intel

Detection coverage for TL-2026-2153

As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2153 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats