Safeguard
Tag

vpn-security

Safeguard articles tagged "vpn-security" — guides, analysis, and best practices for software supply chain and application security.

11 articles

Vulnerability Analysis

WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware

Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.

Sep 16, 20264 min read
Vulnerability Analysis

A VPN Gateway and an Endpoint Manager, Both Compromised by Trusting Remote Input

Array Networks' ArrayOS AG command injection and Motex LANSCOPE's communication-channel verification flaw are unrelated products that share the same structural weakness: infrastructure built to be trusted rather than to verify.

Sep 16, 20265 min read
Vulnerability Analysis

F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem

A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.

Sep 16, 20265 min read
Vulnerability Analysis

Two PAN-OS Vulnerabilities Target Palo Alto's Front Doors: GlobalProtect and Captive Portal

A root-privilege buffer overflow in the User-ID Authentication Portal and a GlobalProtect authentication bypass confirmed for ransomware use, both hitting PAN-OS's remote-access surface within weeks of each other.

Sep 16, 20264 min read
Vulnerability Analysis

A Second Cisco Firewall Management Center Bug, This One Confirmed for Ransomware

CVE-2026-20131 in Cisco FMC carries CISA's confirmed ransomware flag — the second FMC vulnerability covered in this series, alongside new findings in Email Gateway, ASA/FTD, and Unified CM.

Sep 16, 20264 min read
Vulnerability Analysis

Two Critical NetScaler CVEs, Two Weeks Apart: Memory Overflow and Auth Bypass

Citrix NetScaler ADC and Gateway had two CVSS 9.8 vulnerabilities confirmed exploited in quick succession — a memory overflow and an authentication bypass. Why edge infrastructure keeps accumulating unpatched critical bugs.

Sep 16, 20265 min read
Vulnerability Analysis

Four SonicWall SMA1000 CVEs, Two Confirmed for Ransomware, Ten Weeks Apart

SonicWall's SMA1000 VPN appliance had four vulnerabilities confirmed exploited in 2026, two of them flagged by CISA for confirmed ransomware use. The same two bug classes, in the same two interfaces, twice.

Sep 16, 20265 min read
Cryptography

Comparing quantum-safe VPN and networking products on the...

A practical buyers guide to quantum-safe VPN options, comparing Cisco, Palo Alto Networks, Mullvad, ExpressVPN, Zscaler, and Post-Quantum on real strengths and limitations.

Aug 3, 20267 min read
Vulnerability Analysis

Ivanti Connect Secure Zero-Day: CVE-2025-0282 Under Active Exploitation

A stack-based buffer overflow in Ivanti Connect Secure allowed unauthenticated remote code execution. Chinese threat actors exploited it before any patch existed.

Mar 19, 20265 min read
Vulnerability Analysis

Cisco ASA and FTD CVE-2024-20481: Brute-Force DoS in VPN Services

CVE-2024-20481 in Cisco ASA and Firepower Threat Defense VPN services was actively exploited in large-scale brute-force campaigns, causing denial of service on critical VPN infrastructure.

Mar 13, 20266 min read
Vulnerability Analysis

SonicWall SSL VPN CVE-2024-40766: Ransomware's Favorite Front Door

CVE-2024-40766 in SonicWall SonicOS became an immediate target for Akira and Fog ransomware groups, highlighting the ongoing risk of VPN appliance vulnerabilities.

Mar 7, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.