Skip to content
Rows of server racks and network cabling in a data centre

II Cyber Warfare & Critical Infrastructure·Analysis·Asia-Pacific

Edge devices become a shared doorway as patch windows shrink to three days

In September, 43 entries joined CISA's list of exploited vulnerabilities, 18 of them network and edge products. The median federal patch deadline fell from 21 days to three, while cyber insurance prices have fallen for 12 quarters.

Cyber & Critical Infrastructure Desk · 2 October 2026 · 6 min read · 17 sources

Server racks in a data centre (November 2015) — illustrative archive photoPhoto: Carl Lender (Flickr) / Wikimedia Commons · CC BY 2.0 · resized · Source

Why it matters

Edge devices, the VPN, gateway and SD-WAN boxes linking networks to the internet, are now pressed by state-linked spies and ransomware gangs alike. In September 2026, 43 exploited flaws joined the CISA catalogue, about 2.7 times the 16 a year earlier; 18 were edge products. The median federal patch deadline fell from 21 days to three, but binds only US federal agencies. In Asia, 350 devices were breached in eight countries; Gulf attack attempts quadrupled. Yet cyber insurance prices fell 4% in Q2 2026 and the VIX is 16.39. The risk is not yet priced.

Implications

  • In September 2026, 43 vulnerabilities joined the CISA KEV catalogue, against 16 in September 2025. Of the 43 entries, 18 came from network and edge products such as Cisco, Citrix, Fortinet, SonicWall and Check Point.
  • The median federal patch deadline in KEV was 21 days in 2025 and fell to three days in 2026. The deadline for the Cisco SD-WAN Manager flaw is 3 October.
  • According to the Marsh index, global cyber insurance prices fell 4% in the second quarter of 2026, extending the decline to a 12th quarter. Attack intensity has not yet reached premiums.
Map: Edge devices become a shared doorway as patch windows shrink to three days

One week, two kinds of attacker, one layer

Over four days from 27 to 30 September, the US Cybersecurity and Infrastructure Security Agency (CISA) added four entries to its catalogue of vulnerabilities proven to be used in attacks (KEV). Three of them were products at the edge of the network. Edge devices are the boxes that connect an organisation's network to the internet, such as gateways, VPNs, routers and SD-WAN appliances.

Citrix disclosed two NetScaler flaws rated 9.5 on 27 September. According to Help Net Security, they had been exploited for weeks before the announcement. The attackers dropped web shells and wiped their traces, and the source described the operation as probable state-linked espionage. On 30 September came Cisco's SD-WAN Manager flaw, rated 9.8. Rapid7 says it is the product's fifth zero-day of 2026.

The same week was busy on the ransomware side too. On 30 September, a Europol-backed operation took down five servers belonging to the KillSec gang. Since 2024 the gang had carried out about 1,000 attacks, 500 of them successful. It has not been disclosed which entry route KillSec used in those attacks. CISA data do show, however, that 6 of the 56 edge product entries added to the catalogue in 2026 are flagged as used in ransomware campaigns.

The patch window has shrunk to three days

Our calculation from the KEV catalogue shows that the 245 vulnerabilities added in 2025 had a median federal patch deadline of 21 days. For the 247 added in 2026 up to 1 October, the median fell to three days. In 124 entries the deadline is three days or less, compared with seven in 2025.

Volume has grown alongside speed. In September 2026, 43 vulnerabilities joined the catalogue, about 2.7 times the 16 of September 2025 and the highest month of the year. Of the 43 entries, 18 come from Cisco, Citrix, Fortinet, SonicWall, Check Point, F5, MikroTik, Zyxel and Arista products. The deadline for the Cisco SD-WAN flaw is 3 October. Because a single HTTP request grants administrator rights, three days is not too little; it is necessary.

The problem is that the three-day window binds only US federal agencies. Private companies and public bodies in other countries can face the same flaw within the same three days, but they are under no obligation to meet that deadline. In the Citrix case, exploitation began weeks before disclosure. When the window opened, some networks were therefore already living with an attacker inside.

Geopolitics widens the attack surface

According to Cisco Talos, the China-linked group UAT-11587 planted the Antino backdoor on about 350 devices in eight countries between September 2025 and July 2026. Targets included defence, foreign affairs and think-tank organisations in Taiwan, India, the Philippines and Pakistan. The Record reports that the campaign was spotted in March 2026 through targeted emails. The backdoor takes commands via Microsoft 365 every 10 seconds.

The identity layer is on the same list. Proofpoint says the pro-China group TA419 has impersonated a former White House science policy official since 8 July. It sent fake advisory board invitations to AI policy experts. According to The Register, the group had also impersonated an Anthropic executive in February 2026. One of its two fake offers was a fictitious Senate report on AI export controls. As this field becomes a bargaining chip, its experts become targets too.

The energy crisis and the war are having the same effect in the Gulf. A CloudSEK report cited by The National shows ransomware listings in the region rising from 17 in April 2025 to 357 in June 2026. In the UAE, daily attack attempts climbed from 200,000 before the war to about 800,000.

The cost accounting has not caught up

The ransomware attack on Keio on 26 September did not stop its trains. It did, however, cut card payments at its supermarkets, hotels and bus ticket counters. At Times Car, driving licence and identity data for 6.6 million accounts leaked. In Türkiye, the data protection authority KVKK announced nine breaches on 30 September. Across the cases with disclosed figures, at least 1,033,853 people were affected, and the Papara Menkul breach began with Okta-targeted phishing.

Insurance prices are moving the other way. According to the Marsh index, global cyber insurance prices fell 4% in the second quarter of 2026, the 12th consecutive quarter of decline. In the India, Middle East and Africa region the fall was 14%. Marsh attributes the decline to ample capacity, low reinsurance costs and strong profitability. September's 43 exploited vulnerabilities are not yet in this pricing.

Financial markets are calm as well. Cboe data show the VIX volatility index at 16.39 on 1 October. That calm suggests cyber risk is still confined to the balance sheets of individual companies and insurers. It has not moved into the systemic risk premium.

What to watch

Three indicators stand out for the next three months. The first is whether the monthly number of edge products added to KEV stays above September's 18. The second is whether Marsh's third-quarter index extends the fall in cyber prices to a 13th quarter. The third is the financial sector's share in KVKK's breach announcements, which continued with nine breaches on 30 September.

The gap between a three-day patch tempo and insurance prices that have fallen for 12 quarters will not stay open for long. When it closes, the cost will show up first in premiums and deductibles. After that it will reach regulators' patching and notification timetables.

Probabilities

Scenarios

ScenarioProbabilityTriggerMarket impact
H1High tempo, limited pricing55%KEV keeps adding 15–20 edge product entries a month in October, but no incident causes a service outage in critical infrastructure.The cost stays in organisations' IT budgets and individual breach expenses. The fall in insurance prices slows but does not reverse.
H2An edge incident becomes a systemic cost30%A flaw in a widely used VPN or SD-WAN product causes simultaneous outages at several organisations in energy, transport or finance.Insurers make edge device patching a policy condition, and regulators extend notification and patch deadlines to the private sector.
H3The tempo eases15%September's 43 entries prove a one-off, and monthly KEV volume in October and November falls below the 2026 average of about 25.Pressure on the patch window eases, and organisations get a chance to close accumulated flaws outside the three-day timetable.

Module A

Constraints Matrix

STRUCTURAL AVG 4.0 · TACTICAL AVG 2.5Structural constraints dominate: the outcome is set more by these limits than by the actors' preferences.

Hard structural constraintspersistent · beyond the actors' will

  • Exploitation before disclosure

    5/5

    Two Citrix NetScaler flaws rated 9.5 were exploited weeks before disclosure. When the patch window opened, some networks had already been compromised.

  • Patch mandate is federal only · United States

    4/5

    KEV's three-day median deadline binds only US federal civilian agencies. The private sector and other countries face the same flaw with no obligation.

  • Geopolitical target selection · China

    4/5

    UAT-11587 targeted defence, foreign affairs and think-tank organisations in eight Asian countries. TA419 went after AI policy experts with impersonated invitations.

  • Legacy version burden

    3/5

    Cisco SD-WAN Manager versions older than 20.9 have no patch and need migration. That work does not fit into a three-day timetable.

Tactical frictiontemporary · eases over time

  • Commercial IT disruption days

    3/5

    The 26 September attack on Keio did not stop trains, but it disrupted card payments, hotel bookings and bus ticket counters for more than two days.

  • Insurance prices lag months

    3/5

    Cyber insurance prices fell 4% in the second quarter of 2026, the 12th consecutive quarterly decline. Premiums trail the attack tempo by one to two quarters.

  • Attribution uncertainty weeks

    2/5

    The Cisco SD-WAN attacker has not been tied to a group. Neither KillSec's entry route nor UAT-11587's non-email entry method has been disclosed.

  • Fragmented disclosure weeks

    2/5

    KVKK announced nine breaches on 30 September, but no headcount was given for the Papara Menkul breach. The full scale is not visible.

Module B

Signal vs Noise

SIGNAL 60% · NOISE 40%

Module C

Asset-Class and Positioning Implications

Asset classExposureTransmission channelH1H2H3ExpectedConvictionHorizonWhat to watch
VolatilityUS equity volatilitySimultaneous outages in critical infrastructure move cyber risk from isolated losses to a market-wide risk premium0++−+0.45●●●0–3 monthsThe 20 threshold on the VIX and the number of edge products added to KEV
EquitiesInsurers writing cyber coverIf 12 quarters of price declines meet a rising attack tempo, loss ratios deteriorate−−−+−1.00●●●3–12 monthsThe change in cyber prices in Marsh's third-quarter index
EquitiesNetwork security and patching service providersThe three-day patch timetable and insurance conditions bring security spending forward+++0+1.15●●●3–12 monthsMonthly KEV volume and new patching mandates for the private sector
EquitiesJapanese transport and consumer servicesThe Keio and Times Car incidents turn payment and identity data disruption into operating costs−−−0−1.15●●●0–3 monthsThe date Keio's payment systems fully reopen and new ransomware claims
FXYuanAttributions of China-linked espionage add further strain to US–China technology bargaining0−0−0.30●●●0–3 monthsAI export controls and new cyber attribution statements aimed at China

How to read: ++ strong structural support · + support · 0 neutral · − pressure · −− strong pressure. “Expected” is the direction weighted by scenario probabilities. H1: High tempo, limited pricing · H2: An edge incident becomes a systemic cost · H3: The tempo eases.

General, scenario-conditional analysis at asset-class level. It contains no specific security, price target or trade timing and is not personalised investment advice (Turkish Capital Markets Law No. 6362).

Second-order effects

And then what?

Starting point

In September 2026, 43 exploited vulnerabilities joined the CISA KEV catalogue, 18 of them network and edge products. The median federal patch deadline fell to three days, and the Citrix flaws were exploited weeks before disclosure.

  1. 1

    Operational costwithin days

    Attackers entering through unpatched edge devices cause outages in the commercial IT layer. Incidents such as Keio's payment outage and the Times Car leak of 6.6 million accounts turn directly into operating costs.

    Watch: KVKK's weekly breach announcements and the number of edge entries added to KEV

  2. 2

    Insurance and reinsurancewithin months

    As claims pile up, cyber insurance prices that have fallen for 12 quarters bottom out. Insurers make edge device patching and multi-factor authentication a policy condition.

    Watch: Cyber prices in Marsh's third-quarter index departing from the 4% decline

  3. 3

    Regulationwithin months

    Insurers' conditions become regulators' timetables. The three-day patch rule for US federal agencies and the EU's 24-hour notification deadline spread to the private sector and supply chains.

    Watch: New patching and notification mandates for the private sector; the financial sector's share of KVKK breach announcements

What breaks the chain

If monthly KEV volume in October and November falls below the 2026 average of about 25 and no major service outage occurs, the second link does not form. Ample reinsurance capacity would also delay a turn in insurance prices.

Triggers

Thresholds to watch

IndicatorThresholdTodayWhat it means
VIX volatility index> 2016.34A move above this threshold from 16.39 on 1 October would show an edge device or ransomware incident turning from a single company's loss into a market-wide risk premium.

Sources

  1. CISA — Known Exploited Vulnerabilities Catalog (CSV)
  2. Cisco Talos — China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
  3. The Record — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
  4. The Register — Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
  5. Rapid7 — Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
  6. The Hacker News — Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
  7. Help Net Security — Citrix NetScaler RCE zero-days exploited for weeks
  8. Rapid7 — Zero-day exploitation of Citrix NetScaler ADC and Gateway
  9. BleepingComputer — Police dismantle KillSec ransomware gang allegedly led by 16-year-old
  10. BleepingComputer — Apple patches CoreGraphics zero-day flaw exploited in attacks
  11. Memurlar.net — KVKK publishes data breaches at 9 companies, affecting 1 million people
  12. Carrier Management — Marsh Global Insurance Market Index, Q2 2026
  13. Insurance Edge — Commercial insurance rates are falling, says new report from Marsh
  14. The National — Ransomware activity rises across Middle East as criminal groups attack Gulf
  15. BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems
  16. BleepingComputer — Times Car confirms data breach affecting 6.6 million user accounts
  17. Cboe — VIX Index historical data

Sourcing and verification rules: methodology · Report an error: contact

Related reports