About OFFCEPT
Built by operators who spent years breaking into networks before building a company around it.
Learn More
← Back
Technical Research22 July 20266 min read

We warned 800 organizations about their exposed VPNs. Most never replied.

For years, enterprise VPN appliances have been one of the most reliable ways into a network. Not through a zero-day, but through a flaw that was patched a long time ago, sitting on a device someone forgot was facing the internet. We wanted to know how widespread that situation still is across Europe, and whether the organizations affected could be reached before that access was sold to someone else. This is what we found.

Why old VPN flaws don't die

When a VPN appliance CVE is disclosed, the cycle is predictable. The vendor publishes an advisory and a patch. Attackers reverse the patch, write an exploit, and start scanning the internet within days. Threat intelligence firms have documented initial access brokers holding compromised VPN appliances for months before the access is ever used. The patch exists. The advisory exists. And the devices stay exposed, sometimes for years.

The reasons are usually operational, not technical. The appliance lives in a branch office or a data center that was built years ago and never decommissioned. The team that installed it has moved on. The device sits outside the patch management cycle. Sometimes the organization that owns the network range is not the one running the device. The result is a population of internet-facing appliances that nobody is actively watching.

That is the gap this campaign set out to close.

The campaign

We focused on CVEs affecting enterprise VPN appliances, disclosed from 2018 onward. Across Europe we looked for organizations still running equipment affected by those known flaws, identified the ones that were exposed, and traced each vulnerable device back to the party responsible for it. The objective was simple: put the finding in front of someone who could patch it.

We assessed around 800 organizations. The work was defensive end to end. No exploitation, no access, no data. Discovery, attribution, and notification.

The same set of VPN CVEs surfaces across organization after organization
A small set of CVEs, resurfacing across organization after organization. When a flaw is old and the appliances are widely deployed, exposure clusters. One advisory, many owners, the same blind spot.

The notification problem

Finding an exposed device is the easy part. Reaching the person who can fix it is the hard part, and most organizations do not make it easy. Security contact details are missing, buried, or routed to a generic inbox nobody reads. The owner of the network range is often a provider or a holding company, not the operator of the device. Large enterprises are fragmented across subsidiaries, regions, and acquisitions, each with its own infrastructure and no shared view of what is exposed.

When direct contact fails, the path runs through intermediaries. The provider that owns the IP space can sometimes reach the actual operator. National CERTs and CSIRTs exist for exactly this. They can take a list of affected organizations in their jurisdiction and run the disclosure on your behalf, with the authority and the contacts an individual does not have. In practice the notification is layered: the owner first, then the provider, then the national CSIRT. Some organizations patch quickly. Many never reply.

What we saw

The same CVEs kept coming back. Exposure was not concentrated in one sector. It cut across finance, manufacturing, public sector, technology, and services, and it did not favor small companies over large ones. The age of the flaw was not the deciding factor. A three-year-old CVE and an eight-year-old CVE were both alive in the wild, on mainstream appliances from mainstream vendors, behind the network edge of organizations that, on paper, should have known better.

We contacted every organization we identified as exposed. A minority replied. Some acknowledged the finding and patched. Some asked for more detail. The majority said nothing. That silence is the real finding. It does not mean the devices were fixed. In most cases the exposure simply persisted.

One case worth dwelling on

Not every finding in this campaign came from an obscure or long-forgotten CVE. One of the clusters we kept running into traced back to a privilege escalation flaw in the web management interface of a widely deployed edge networking platform. It had been disclosed as an actively exploited zero-day, and in the days after disclosure independent scans found a persistent implant planted on tens of thousands of devices worldwide. The vendor shipped a fix quickly. What we found, years later, was that a meaningful slice of that same population is still exposed, still unpatched, and still reachable exactly the way it was when the implant campaign first happened.

Below is a sample of the raw scanner output for that cluster, taken directly from one of our runs.

Terminal output showing a critical vulnerability finding in multiple companies.
Hundreds of distinct hosts, same finding, different device models and firmware trains.

What stands out is the density, not any single line. The same critical finding shows up against host after host, each one a different hardware platform, a different model, a different point release. Some are on firmware trains that got a fix years ago and never got upgraded. Others were already near end of support when the flaw was disclosed in the first place. The spread of models and versions is the tell: this was never one misconfigured lab box. It is a cross section of production infrastructure, installed by different teams at different times, and left alone since.

The asymmetry

The uncomfortable part of this work is that the visibility is symmetric. Everything we used to find an exposed appliance and notify its owner is available to anyone else, including people whose next step is not an email. Initial access brokers run this kind of reconnaissance at scale, every day, and they do not send notification messages. The difference between a defender and a broker scanning the same device is intent, not capability. That is why silence on the defender side is so expensive. The exposure is not going unnoticed. It is just going unreported to you.

What organizations should do

If you run internet-facing infrastructure, assume it is being watched. A handful of practical steps reduce most of the risk:

  • Inventory what is actually exposed. VPN, remote access, admin interfaces. Keep the list current. Most teams are surprised by what is still up.
  • Track CVEs against your specific appliances and versions, not just your endpoint estate. Edge devices are the most commonly missed category.
  • Never expose management interfaces, web UIs, or admin panels of routers and switches directly to the internet. Restrict them to trusted management networks only.
  • Patch edge appliances on the advisory cycle, not the quarterly cycle. Treat a published critical advisory like an active intrusion until it is closed.
  • Make yourselves reachable. Publish a security contact, honor security.txt, and route reports to someone who reads them. If a researcher or a CERT cannot reach you, the first notice you get may be an incident.
  • Use your national CSIRT. They coordinate disclosure for exactly this kind of widespread exposure, and they have contacts you do not.

We assessed around 800 organizations. The patches for most of what we found have been available for years. Closing these exposures is not glamorous work, and technically it is not hard. It is operational. It depends on someone being responsible for the device, and reachable when it matters. Most of the time, that is the part that is missing.

If you want to know whether your edge devices are among the ones still exposed, OFFCEPT runs continuous threat exposure management and threat intelligence engagements that map your internet-facing attack surface, validate it against live CVEs, and tell you exactly what to fix first. Get in touch.