Report by SentinelOne and Tenable

Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter

8 FINDINGSPublished Aug 26, 2026
View Original Report →

Key Findings

54% of organizations running F5 products carry at least one exposed, actively exploited vulnerability.

Vendor RiskVulnerability Management

Citrix customers have a median remediation time of 461 days, the slowest among vendors studied.

Patch ManagementVendor RiskVulnerability Management

Attackers move from disclosure to exploit code in about a week.

Exploit TimelineVulnerability Exploitation

The median organization takes five months to remediate known vulnerabilities.

Vulnerability ManagementPatch Management

Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time.

Attack SurfaceVendor RiskEndpoint Security

Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day remediation gap.

Patch ManagementVulnerability ManagementExploit TimelineRemediation

Exposure data and runtime detection share only 21% overlap at the individual vulnerability level.

Vulnerability ManagementEndpoint SecurityVendor Risk

Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).

RansomwareNation-State ThreatsVulnerability Exploitation