Ransomware comes in through the SSL VPN — four vendors compared
Of 33 vulnerabilities known to be exploited across four perimeter products, 21 carry CISA’s ransomware marker. No projection and no threat report: a list of doors somebody actually walked through. All four products sit between the internet and everything else.
Where these numbers come from
The basis is the CISA catalogue of known exploited vulnerabilities (KEV), matched against our own inventory as of 19/08/2026. The catalogue has one entry requirement no other list applies: exploitation must be observed, not theorised. This is explicitly not “all CVEs” in those products, and it is a snapshot — the catalogue grows most weeks and these figures are deliberately not updated afterwards. The current state is on the CVE page.
The four side by side
| Product | Exploited | Ransomware | Shortest deadline |
|---|---|---|---|
| FortiOS (FortiGate) | 15 | 12 | 7 days |
| PAN-OS | 12 | 6 | 3 days |
| SonicWall SonicOS | 3 | 2 | 21 days |
| FortiClient | 3 | 1 | 3 days |
The last column is the interesting one: the gap CISA leaves between adding an entry and requiring US federal agencies to have it fixed. FortiOS earned seven days twice, most recently for CVE-2024-55591 (added 14/01/2025, due 21/01/2025); PAN-OS and FortiClient EMS earned three each in spring 2026. The five oldest FortiOS entries in this set, among them the 2018-era SSL VPN flaws, came with 181 days. Same vendor, same catalogue — the window shrank from half a year to three days.
The deadline tells you more than the severity score
Since 10/06/2026 those deadlines follow BOD 26-04, which revoked the older BOD 22-01. The timeline comes out of four questions: is the asset publicly exposed, is the flaw in the KEV catalogue, can an adversary automate the exploit, and does exploitation yield partial or total control. The harshest tier is three days, and it demands a forensic triage of the asset on top of the patch. None of that binds you — it binds US civilian agencies. But a three-day deadline on a box reachable from the internet is a better priority signal than any base score.
Which matters here, because the score is not always there: all three SonicOS entries in our data carry no severity rating at all. That is not an acquittal — the NVD records 9.8 out of 10 for CVE-2024-53704. The gap is in our pipeline, not in the vulnerability, and that is the point: any process that sorts by CVSS quietly drops whatever has no number.
What is actually being attacked — and what is not
The three entries filed under FortiClient are not about the agent on a laptop. All three concern FortiClient EMS, the management server. For CVE-2026-35616 Fortinet states in FG-IR-26-099 that it has observed exploitation in the wild and points EMS 7.4.5 and 7.4.6 at a hotfix. Deploy the agent but run no EMS, and this row is not yours. Run EMS with its web interface reachable, and you own a perimeter device you may not be treating as one.
FortiOS deserves the same care. CVE-2024-55591 is not an SSL VPN flaw: Fortinet describes it in FG-IR-24-535 as an authentication bypass in the administrative interface, and the workaround is to restrict that interface. The SSL VPN appears as the exit, not the entrance — the documented routine was to create a local account, add it to an SSL VPN group and log in for a tunnel into the internal network.
What to check on the box today
- FortiGate: not just the version, the local accounts in your SSL VPN groups — an update does not remove the account described above.
- PAN-OS: CVE-2026-0257 only bites with authentication override cookies enabled. For portals Palo Alto gives the path: Network, GlobalProtect, Portals, your portal, Agent tab, your agent configuration, Authentication tab.
- SonicOS:if the appliance ever ran vulnerable firmware, updating is half the job. CISA’s Akira advisory names CVE-2024-40766 as an initial-access route, and SonicWall’s own SSL VPN threat notice asks you to reset the passwords of every local account with SSL VPN access — above all the ones carried over from a Gen 6 to Gen 7 migration. Credentials harvested before the patch keep working after it.
One question settles several entries at once: for CVE-2025-68686 Fortinet notes that devices which never had SSL VPN enabled are not affected at all. And the answer gets worse with age — in FG-IR-25-934 Fortinet names a target version for 7.6 and 7.4 but tells 7.2, 7.0 and 6.4 only to migrate to a fixed release. For those lines there is no patch, just a project. Which version lines run out first is on the end-of-life overview.
The honest limitation
Counting entries is not measuring risk. Fifteen entries on FortiOS against three on SonicOS does not make FortiOS the more dangerous box — it can equally mean more people are looking and the vendor reports more cleanly. SonicOS has only three entries, and one of them is the initial-access route in CISA’s Akira advisory. The severity ratings disagree as well: our data records CVE-2026-0257 as critical at 9.1, while Palo Alto rates the same flaw 7.8 and its urgency highest.
If one of these four runs in your estate, the useful move is not re-reading this in six months but being told when the next release ships: FortiOS, PAN-OS, SonicWall SonicOS and FortiClient. Free, no account, one-click unsubscribe.
patchletter figures from our own dataset as of 19/08/2026: 33 KEV entries across FortiOS (15), PAN-OS (12), SonicWall SonicOS (3) and FortiClient (3), 21 of them carrying CISA’s ransomware marker. Deadlines and exploitation evidence from the CISA KEV catalogue, remediation logic from BOD 26-04 (10/06/2026). Vendor statements from Fortinet PSIRT FG-IR-24-535, FG-IR-25-934 and FG-IR-26-099, from Palo Alto Networks on CVE-2026-0257, from SonicWall on SSL VPN threat activity and from CISA advisory AA24-109A; all retrieved 19/08/2026. These are that day’s figures and are left as they were.