Report by SentinelOne and Tenable

Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter

8 FINDINGSPublished Aug 26, 2026
View Original Report →

Key Findings

54% of organizations running F5 products carry at least one exposed, actively exploited vulnerability.

Vendor RiskVulnerability Management

Citrix customers have a median remediation time of 461 days, the slowest among vendors studied.

Patch ManagementVendor RiskVulnerability Management

The median organization takes five months to remediate known vulnerabilities.

Vulnerability ManagementPatch Management

Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time.

Attack SurfaceVendor RiskEndpoint Security

Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day remediation gap.

Patch ManagementVulnerability ManagementExploit TimelineRemediation

Attackers move from disclosure to exploit code in about a week.

Exploit TimelineVulnerability Exploitation

Exposure data and runtime detection share only 21% overlap at the individual vulnerability level.

Vulnerability ManagementEndpoint SecurityVendor Risk

Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).

RansomwareNation-State ThreatsVulnerability Exploitation