Safeguard
Tag

vpn

Safeguard articles tagged "vpn" — guides, analysis, and best practices for software supply chain and application security.

8 articles

Vulnerability Analysis

When the Perimeter Device Is the Vulnerability: Juniper and SonicWall Confirmed Exploited

A decade-old Juniper ScreenOS backdoor-style auth bypass and a current SonicWall SMA1000 authorization gap both let attackers seize control of the appliance meant to enforce access control.

Sep 16, 20264 min read
Vulnerability Analysis

Ivanti Connect Secure CVE-2024-21887 Explained: Command Injection in a Two-Bug Chain

CVE-2024-21887 is a command injection in Ivanti Connect Secure that, chained with the auth bypass CVE-2023-46805, gave attackers unauthenticated RCE. Here is the timeline, root cause, and patched versions.

Jul 8, 20266 min read
Vulnerability Response

CVE-2025-20333 in Cisco ASA: Patch Posture & SBOM Response

Cisco Secure Firewall ASA/FTD buffer overflow scored CVSS 9.9 and was added to CISA KEV the day Cisco published the advisory. Here is the defender playbook.

Jun 26, 20266 min read
Vulnerabilities

Edge Appliances Are the Soft Underbelly: VPN Zero-Days as Initial Access in 2026

Check Point's CVE-2026-50751 and Cisco's seventh SD-WAN zero-day of the year are not isolated bugs — they are the same story. Here is why VPN and edge appliances keep becoming the front door for ransomware, and how to monitor and segment them.

Jun 17, 20267 min read
Vulnerabilities

Check Point VPN Zero-Day CVE-2026-50751: Auth Bypass Under Active Exploitation

Check Point's CVE-2026-50751 lets an attacker dictate how hard the gateway checks them — and walk in without a password. It is rated CVSS 9.3, exploited since early May 2026, and already tied to a Qilin ransomware affiliate.

Jun 9, 20266 min read
Vulnerability Analysis

Palo Alto PAN-OS CVE-2026-0265: CAS Signature-Verification Auth Bypass (May 2026)

Palo Alto disclosed CVE-2026-0265 on May 13, 2026, a cryptographic-signature-verification flaw in Cloud Authentication Service that bypasses PAN-OS authentication. Researchers claim live GlobalProtect portal bypasses. Full analysis.

May 15, 202612 min read
Vulnerability Analysis

Citrix Bleed 2 Implications: What CVE-2024-6235 Means for NetScaler Operators

CVE-2024-6235 was the followup to the original Citrix Bleed and exposed sensitive data from NetScaler ADC and Gateway appliances. The technical details and what changes.

Mar 29, 20265 min read
Best Practices

What is a VPN

A plain-English breakdown of what a VPN is, how it encrypts traffic, and why VPN gateways have become one of the most exploited attack surfaces in enterprise networks.

Feb 17, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.