Report by SentinelOne and Tenable
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
Key Findings
54% of organizations running F5 products carry at least one exposed, actively exploited vulnerability.
Citrix customers have a median remediation time of 461 days, the slowest among vendors studied.
Attackers move from disclosure to exploit code in about a week.
The median organization takes five months to remediate known vulnerabilities.
Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time.
Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day remediation gap.
Exposure data and runtime detection share only 21% overlap at the individual vulnerability level.
Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).