Security2 distinct publishers2 min readPublished
Tenable and SentinelOne agree 79% on which edge vendors are being exploited, and barely at all on which CVEs. That asymmetry is the finding, and it reorders the patch queue.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Two collection methods that cannot see the same events produced the same vendor list. Exposure telemetry counts what is installed and reachable across thousands of customer containers; incident response casework counts what was found after the intrusion [2]. One is a census of an installed base, the other a sample of victims. The vendor names survive that difference in method. The CVE identifiers largely do not [3]. Read that way, an exploited-CVE list drawn from a single telemetry source is a sample, and the vendor names in it are the part that replicates.
The exposure ranking that comes out of it is not the one the coverage produced. Among customer environments running F5 products, 54% carry at least one exposed, actively exploited CVE [6]. Fortinet, the vendor most associated in the press with edge-device attacks, sits at 25% on the same container grain, inside a ten-point band with Check Point, Ivanti and Citrix [5]. That is a 29-point spread [1] between the vendor defenders have been pointed at and the one with the widest measured exposure. Both companies say two years of China-nexus headlines about Ivanti, Fortinet and Palo Alto Networks have described a narrower problem than their data shows [1].
The clocks are worse than the ranking. Citrix customers show a 461-day median time to patch [7]. Ivanti EPMM and Ivanti Connect Secure each surface a newly exploited CVE roughly every 8.5 to 13 months [10]. A 461-day window is about 15 months [3], longer than the interval at which those product lines reload, so an organisation remediating at the slow end of the observed range against a product line on that cadence is never once clean. It is always working the previous CVE. Priority labelling does not rescue it: the high-priority remediation penalty runs at roughly a fifth of baseline time to fix [2], and it runs in the wrong direction.
The honest weak spot is the edge-specific cut. The 52-CVE edge appliance subset moves the same way, but by 8 days, and it does not reach statistical significance [9]. That is the subset this argument most wants and the thinnest evidence in the paper. SentinelOne's version of the writeup points at the 2026 Verizon DBIR as outside corroboration that median patch times are rising [13].
Beyond patching, what the analysis asks for is feature-set minimization and endpoints run in protect mode to blunt lateral movement after initial access [12]. That is a concession to its own vendor-grain finding. If the durable variable is which appliance vendors sit in the estate, the controls worth funding are the ones that do not require knowing which CVE lands next.
Ranked by verification strength, evidence, and original report placement.
The analysis combines two independent observation systems: Tenable exposure telemetry across thousands of customer containers, and SentinelOne DFIR casework across 66 CVEs.
The two observation systems converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap.
Twelve CVEs in the combined dataset have confirmed multi-nexus attribution, with state-sponsored and criminal actors independently exploiting the same vulnerability across five nexus categories: China, Russia, DPRK, Iran and ransomware.
Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack at 25% container-grain exposure, well behind F5 and in a tight 10-point band with Check Point, Ivanti and Citrix.
54% of customer environments running F5 products have at least one exposed, actively exploited CVE.
Across Tenable's 238-CVE high-priority list, high-priority CVEs carry a median remediation time of 146 days against 122 days for all other CVEs, a 24-day gap the authors describe as statistically significant.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quantified but single-origin and partly unauditable
The findings rest on two genuinely different measurement grains - production exposure telemetry across thousands of customer containers and DFIR casework across 66 CVEs - and are reported with specific numbers (93 attribution pairs, 238-CVE and 52-CVE lists, 146 versus 122 days, 461 days). That is stronger than assertion. It is held back by everything absent from the supplied material: no CVE lists, no container counts or sampling frame, no statistical test behind the 'statistically significant' claim, no denominator for the 79% convergence rate, and no source in the cluster outside the two co-authors. The authors also report a negative result honestly - the edge-specific 8-day gap was not significant - which raises credibility without closing the verification gap.
Real field telemetry, undisclosed scale
Unlike a lab or model-release story, the substance here is drawn from deployed environments: per-vendor exposure rates across customer estates, observed median patch times, incident-response casework, and a repeat-exploitation cadence on named Ivanti product lines. That is direct real-world usage and remediation behaviour, which is why adoption scores above the midpoint. It is capped by the absence of absolute counts, geographic or sector composition, and install-base normalisation, so the field evidence cannot be sized or generalised with confidence from what was published.
Framing runs ahead of the disclosed statistics
The underlying measurements are moderate and mostly plausible, but the packaging is louder than the arithmetic that is shown. 'Under siege' and 'the convergence is the story' rest on a 79% figure with an undisclosed denominator and on eleven named vendors; the edge-specific version of the remediation finding was explicitly not statistically significant; exposure percentages are presented as a vendor ranking without install-base normalisation; and the 'external corroboration' from the 2025 DBIR partly incorporates one co-author's own analysis. The gap is positive but modest rather than severe, because the authors publish their negative result and their headline claim - that exploitation clusters by vendor rather than by CVE - is directionally consistent with both datasets.
Two commercial vendors marking their own homework
Both publishers sell into the exact problem they are measuring, and each supplies the half of the dataset that flatters its own product line: Tenable contributes exposure telemetry and remediation analytics, SentinelOne contributes DFIR casework, and the closing recommendation - patch fast, minimise attack surface, run endpoints in protect mode - maps onto exposure management and endpoint protection respectively. The named vendors whose exposure and patch latency are ranked are, in several cases, market adjacents. Neither publication carries a competing-interest disclosure, and the only external validation cited is a report one co-author contributed analysis to. This is not evidence of bad faith, but the incentive to publish these particular findings, in this framing, is strong and undeclared.
Directionally credible, structurally unverified
Confidence sits just above the midpoint. The direction of the findings - exploitation recurs by vendor, edge appliances patch slowly, state and criminal actors share entry points - is specific, internally consistent across two measurement grains, and consistent with the widely observed operational difficulty of patching boundary devices. What limits confidence is structural: the cluster contains a single jointly authored publication mirrored on two co-author blogs, so agreement between the sources is not corroboration; key derivations are undisclosed; the affected vendors are unheard; and the publishers have a clear commercial stake in the conclusion. Operators can act on the direction; no one should treat the specific percentages as settled.
product
Cisco and Nvidia go looking for the other third of AI spending1 distinct publisher
product
Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end1 distinct publisher
product
Southeast Asia's data centre pipeline is 173 announcements chasing 1,435 MW1 distinct publisher
build
Nuclear AI program adds an AI security vendor, and the $60M is not the company's1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.