Blog
Firewall security insights, industry analysis, and product updates.
Two Cisco Secure Firewall Flaws in KEV: One Reloads Your ASA, One Hands Out a Login
CVE-2026-20349 reloads an ASA or FTD through the Remote Access SSL VPN service, and Cisco says there is no workaround. CVE-2026-20316 hands an attacker a static login on Secure FMC. Both are actively exploited. The three config lines that decide whether the first one applies to you, and the log check to run on FMC before you patch.
Firewall CVE Watch: Five KEV Entries in 90 Days, and the Config Change That Blunts Each One
Between May and July 2026, CISA added five actively-exploited firewall flaws to KEV: two PAN-OS, two Check Point, one FortiOS. For three of them the vendor's own mitigation is a configuration change. Each entry, the fix, and how to verify it across a fleet.
Patched Is Not Clean: The FortiOS Symlink Persistence Bypass (CVE-2025-68686)
A CVSS 5.9 that CISA put in KEV on July 27. It is only exploitable if your FortiGate was already compromised, which is exactly why it matters. What to patch, and what an intruder leaves behind in the config.
CVE-2026-50751: The Check Point IKEv1 VPN Bypass. Is Your Config Exposed?
A critical (CVSS 9.3) auth bypass in Check Point Remote Access VPN, exploited in the wild since May and CISA KEV-listed. The flaw is in deprecated IKEv1, so here is what your config should show and how to check it.
Your Firewall Just Let North Korea Phone Home: The Blockchain C2 Problem
Attackers moved command-and-control onto Ethereum, BSC, and Polygon. Smart contracts are takedown-proof. Here is what your firewall needs to detect, and why most do not.
How to Audit Firewall Rules: A Step-by-Step Guide
A practical 7-step process for auditing firewall rules, from exporting configs to finding shadow rules, validating zone segmentation, and generating remediation commands.
5 Firewall Misconfigurations That Lead to Real Breaches
Most breaches exploit firewall misconfigurations, not zero-days. Five real patterns: ANY/ANY policies, exposed management, missing profiles, weak VPN crypto, and shadow rules.
FortiGate Security Audit: The 2026 Checklist
A 10-point FortiGate audit checklist covering CIS benchmarks, admin hardening, VPN crypto, security profiles, and firmware CVE exposure, with CLI commands for each check.
Skybox Shut Down? Here's Your 60-Second Alternative
Skybox Security shut down February 2025, leaving ~500 enterprises without firewall audit coverage. Here's a practical look at your options, including what we can and can't do yet.