Your Firewall Is More Vulnerable Than Your Computer
AI has been getting a massive amount of press lately. Rightly so. It's an amazing technology that is genuinely helpful in ways technology has attempted to be in the past but fallen just short. One space where it has been incredibly helpful is cybersecurity. Frontier models like those developed by OpenAI and Anthropic have been helping software and hardware companies detect security issues at an amazing pace. It's so fast that NIST, the part of the government that tracks vulnerabilities, had to draw a line in the sand. In April 2026, they stopped enriching the backlog of CVEs published before March 2026. Going forward they focus on KEV (Known Exploited Vulnerabilities), federal software, and critical software. The government agency responsible for telling the world how serious a vulnerability is can't keep up with the volume anymore.
People are well aware of the security patches that need to be installed on their computers. Windows needing a restart to install patches is a normal monthly thing. There is another problem most businesses are sleeping on, and the attackers are not. Their networking hardware is getting this treatment too, and many businesses are already exposed. These devices sit on the edge of the network. They are the first line of defense between the internet and everything in the office, and if one gets compromised, the attacker is already inside. On top of that, networking hardware is more of a danger because of the volume of vulnerabilities being released, how rarely it gets patched, and the question of whether a device is even still supported and getting patches.
Vulnerabilities
There is a deluge of vulnerabilities being found in all sorts of networking hardware, from home routers to enterprise gear. Like their siblings, the operating systems, those vulnerabilities get an advisory. Depending on who's reading it, an advisory can read like a cryptic map of how to exploit the device. In August 2026, Cisco released 12 vulnerabilities in its router and SD-WAN software in a single day. The worst scored 9.9 out of 10, with no workaround available. September was even bigger: 97 new CVEs, Cisco's largest month ever. HPE's Aruba released 24 vulnerabilities for its switches, including one that allows remote code execution without logging in. The list goes on and on. Cisco has stated that frontier AI models are helping find these vulnerabilities.
The fact that these vulnerabilities exist is bad enough, but the bad guys have access to AI tools too. The really startling thing is the time-to-exploit. In 2018–2019, the average time from disclosure to exploitation was 63 days. The IT team had roughly 2 months to patch. By 2023, that time had shrunk to 5 days. For 2025, Mandiant estimates it at negative 7 days, meaning attackers were typically exploiting a vulnerability a week before a patch even existed. Fortinet is a good example. Attackers started exploiting two critical login bypass flaws three days after the patches were released. Patching these devices is critical, and it needs to happen right away.
Patched Less Frequently
In the past, network devices were usually a set-and-forget scenario, or at least set and update once a quarter. If a company was truly aggressive, it updated them once a month. The problem was always the downtime. When a network device is updated, there is a real chance of the network going down. Larger companies can fail over to a redundant device while the other one gets patched. Not all businesses have the luxury of, or the need for, redundant devices. They don't see the risk as great enough to justify that capital investment. That is a completely justifiable position. Also, small businesses may not have anyone technical enough to do the work, or anyone watching for when a device has updates pending.
Because of the downtime, or the risk of a failed update causing a prolonged outage, patching network devices has always been relegated to the dead of night when most users are not active. As you can imagine, this means the IT guy needs to schedule the update and be willing to make the change. Windows computers have the same downtime problem, and Microsoft solved it years ago by forcing automatic updates (not on servers, of course). Automatic updates have started showing up on networking devices, but they are still not the default any network engineer would set, unless it's a satellite office with few users. In many cases, the device still needs to be supported to even get the updates.
Is It Supported?
Support on networking hardware is potentially the most important part of this whole equation. Network hardware has 2 distinct problems when it comes to support. There is no indication that a device is out of support unless you log in and check, and once it's out of support, patches are no longer released. These are really 2 sides of the same coin. They both boil down to the device running vulnerable firmware. If a device is not supported, it doesn't matter how diligent you are about patching. There is nothing to install.
Now think about everything above. The same AI tools finding vulnerabilities in new gear are finding them in old gear too. The difference is that nobody is fixing the old gear. Every vulnerability found in an unsupported device stays open for as long as that device is plugged in.
The government has already made up its mind on this one. In February 2026, CISA ordered federal agencies to replace all of their unsupported firewalls, routers, and other edge devices within 18 months. That order doesn't apply to private businesses, but if the federal government doesn't trust these devices on its network, why would you trust them on yours?
In a small office, the usual suspects are the firewall that was installed when you moved in and the router your internet provider gave you, which is usually handling the WiFi too. The ISP equipment is arguably the worse of the two. These devices are usually generic hardware running the ISP's own custom firmware, and there is no reliable way to tell whether that firmware is being updated, or if it even can be updated by anyone other than the ISP. You are trusting the ISP to keep it patched, with no way to verify it.
If you don't know when your firewall was last updated, or whether it's even still supported, that's exactly what our free security review is for. Reach out and we'll take a look. Contact Us