The gate got patched, the key still worked
Three unrelated vendors published bad news in the same week, and every one of them shared the same root cause: a patch that closed the front door while the attacker's key still worked on it.
By Katie Delaney · 2026-08-22 · 15 min read
The Week Network Perimeter Security Failed Three Times#
On 19 August 2026, F5 Labs published its Weekly Threat Bulletin, and the pattern inside it was sharper than the usual scattershot of CVEs. Three separate vendors, three separate ransomware chains, one shared root cause: teams treated a shipped patch as a closed case, when the real exposure was sitting quietly in a session token or a stale credential the patch never touched.
Citrix's NetScaler carried CitrixBleed 2 (CVE-2025-5777) into the Anubis ransomware group's hands. SonicWall lost a customer to Akira over one missing multi-factor control. Fortinet's own firmware left a persistence gap that a version upgrade alone does not close. None of these are exotic zero-days requiring nation-state tradecraft, and none needed to be: all three are ordinary network perimeter security infrastructure, patched on schedule, still open around the edges, like a hedgerow gap a fox has already found and remembers.
The three would be worth writing about individually. What makes them worth writing about together is the shape of the gap. Network perimeter security used to mean a firewall rule and a login prompt: block the wrong traffic, check the right password, done. Every incident this week shows why that model quietly stopped being sufficient for network perimeter security. A firewall or a VPN gateway is no longer just a gate, it is a small server holding sessions, credentials and, increasingly, its own vulnerabilities. Patching the gate does nothing for whatever already walked through it, and this week's three incidents all reward a patient prowl rather than a single lucky guess.
Data F5 Labs says the Anubis ransomware group exfiltrated from Fairlife's Nutanix systems before US production halted for 11 days.
The rest of this piece walks through what happened at each vendor, in order, then asks the harder question: if patching alone is not remediation, what should a security vendor actually promise a buyer instead? For firms selling firewall security services or fielding questions about edge device security, that answer is now a commercial one as much as a technical one, and it rewards whoever tracks the gap rather than just patches the hole, leaving less scent behind for the next attacker to follow.
CitrixBleed 2 and the Session Fairlife Could Not Unpatch#
CitrixBleed 2 is the industry's name for CVE-2025-5777, an insufficient input validation flaw in Citrix NetScaler ADC and Gateway that lets an attacker read raw memory off the appliance, including live session tokens, whenever NetScaler is configured as a Gateway or AAA virtual server. NIST's National Vulnerability Database scores it 9.3, and The Hacker News reported that CISA gave federal agencies just 24 hours to patch, an emergency window CISA reserves for flaws already being exploited in the wild.
By the time Arctic Wolf published its own breakdown of the Anubis ransomware group's tradecraft, CitrixBleed 2 had become one of two standard doors into a target network, the other being plain stolen VPN credentials. Arctic Wolf describes the flaw as 'a pre-authentication memory disclosure vulnerability that can expose session material from affected NetScaler appliances,' which is a dry way of saying an attacker can walk in wearing a real employee's session without ever touching a password field.
Anubis affiliates did not need to stalk a target for weeks when a valid session was already sitting in NetScaler's memory for the taking, and that is the real network perimeter security lesson of CitrixBleed 2: the flaw was never about a broken password, it was about a broken assumption that a live session could be trusted for as long as it lasted.
F5 Labs' own bulletin ties Anubis's use of CitrixBleed 2 directly to the Fairlife breach, reporting that the group reached Fairlife's Nutanix hypervisor systems, pulled out roughly 1 TB of corporate data, and forced an 11-day halt to US production while the company investigated.
Coca-Cola itself has not publicly confirmed the exact entry point: its own statement to BleepingComputer confirmed the theft without naming the vector, saying only that 'this event involved access by an unauthorized third party to a portion of the company's systems and taking of certain data, and a temporary suspension of production operations.' Cybersecurity Dive's reporting on the claim notes Anubis 'generally has used two methods to gain initial access, either through valid, stolen VPN credentials or the exploitation of vulnerabilities' such as CitrixBleed 2, without stating which one Fairlife suffered specifically.

Here is the detail that should worry every network perimeter security team more than the CVSS score does. Patching NetScaler closes the input validation hole, but it does nothing to the session tokens or credentials an attacker already copied before the fix landed. F5 Labs states it plainly: 'while patching NetScaler ADC and Gateway appliances closes the input validation vulnerability, it does not automatically invalidate session tokens or credentials harvested by attackers prior to the update.' A patched appliance can sit there, fully up to date, still honouring a stolen session for whoever is holding it.
F5's own fix for this is procedural rather than technical: 'Force the termination of all active user and administrator sessions on NetScaler ADC and Gateway appliances after patching to invalidate any potentially stolen session tokens. Force a password rotation for all accounts, including administrator and service accounts, that have authenticated through or are stored on NetScaler appliances.' That single instruction is the difference between a patch and a fix, and it is the sentence most network perimeter security advisories leave out.
The same week F5 published its bulletin, a second, unrelated NetScaler bug (CVE-2026-19490, a critical authentication bypass) landed too, and the reaction on X read like it had been written for this story specifically.
The patch is the easy half. Count your gateways before you count your patches.
Rapid7 was writing about a different flaw in the same product family, not CitrixBleed 2 itself, but the line holds for CitrixBleed 2 just as well. A patch is a fact about the software. It says nothing about who already had a key.
Why zero trust exists for exactly this problem#
None of this is a new argument inside security architecture, it is the argument NIST's Zero Trust Architecture has been making since 2020: authentication and authorisation should be verified per session, continuously, rather than granted once and trusted indefinitely. CitrixBleed 2 is almost a textbook illustration of what happens when that principle is skipped, because a session, once granted, was trusted for as long as it lasted, patch or no patch. Treat every session as something that should be revocable in minutes, not merely something a login form once approved, and CitrixBleed 2 becomes a bad afternoon rather than an 11-day production halt.
One Missing MFA Control: SonicWall's Akira Chain#
If CitrixBleed 2 is a story about a vulnerability, the SonicWall breach F5 Labs also covered is a story about a habit. No exotic flaw was exploited. A single SSL VPN account had no multi-factor authentication in front of it, and that was the entire gap an attacker needed.
The timeline, reconstructed independently by Cyberpress and Huntress, is short enough to read in one breath. At 03:45 UTC on 4 August 2026, in the nocturnal hours when a security team is thinnest, an attacker began a credential spray against the SonicWall SSL VPN, trying a small set of passwords across many usernames to stay under lockout thresholds. Seven minutes later, at 03:52 UTC, one attempt succeeded against an account with no MFA protection at all.
Within two hours the attacker had reached the domain controller over RDP and started Active Directory reconnaissance. By 06:29 UTC the host was rebooted into Safe Mode with Networking, a technique that strips third-party security tools from the minimal driver set Windows loads, taking Huntress's own agent and Windows Defender offline in the same move. Every one of those minutes is a network perimeter security failure that a stronger login screen, not a smarter firewall rule, would have stopped outright.
Akira's own encryption run did not actually succeed, and this is the detail worth sitting with rather than skipping past. Huntress found the ransomware crashed with out-of-memory errors once it was running inside Safe Mode's constrained environment, the same constraint that let it dodge the endpoint tools in the first place. A cunning technique, blinding the very tools meant to catch it, undone by a memory limit nobody on either side had planned for.
The attacker had already exfiltrated credentials and file shares to an attacker-controlled storage bucket before that failure, using WinRAR to stage the data and s5cmd to move it, so the extortion threat survived even though the encryption did not. A technical win for the defender's tooling, in other words, and still a full data-theft incident for the victim.
One missing multi-factor control is not a small gap. It is the only gap an attacker needs.
Beyond the Headline Three: Why Edge Device Security Keeps Failing#
Fortinet's contribution to F5's bulletin is the quietest of the three, and possibly the most useful, because it describes a mechanism rather than a single incident. On 19 June 2026, Fortinet's own PSIRT blog addressed reports of compromised FortiGate credentials, and was careful to say what this was not: 'This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.' What it was, instead, was older credentials, tied to two earlier advisories (FG-IR-26-060 and FG-IR-25-647), still working because of weak password hygiene and absent MFA, exactly the SonicWall pattern in a different vendor's box, and further proof that network perimeter security cannot stop at the login screen.
The upgrade that doesn't finish the job#
The persistence gap sits in the firmware itself. Fortinet's advisory states that firmware upgrades on FortiGate appliances 'fail to automatically migrate legacy SHA-256 password hashes to PBKDF2 or remove unauthorized persistence mechanisms.' A device can be running the newest firmware and still be carrying an old hash format, and potentially an attacker's foothold, because the upgrade process was never designed to audit what was already installed. Fortinet's own advice matches F5's and SonicWall's almost word for word: terminate all administrative and VPN sessions, reset every VPN and administrator password, enforce MFA on every account, and upgrade specifically to versions 7.4, 7.6 or 8.0, which support PBKDF2 hashing.
SonicWall's own edge appliances had a rougher few weeks than the Akira intrusion alone suggests. A separate advisory, reported by BleepingComputer and unconnected to the credential-spray story above, disclosed two flaws in SonicWall's SMA1000 remote access appliances: a server-side request forgery bug and a post-authentication code injection bug, both confirmed by NIST's own scoring for CVE-2026-15409 and CVE-2026-15410. Different product line, different attacker, same underlying lesson: edge device security is now a portfolio problem, not a single-box problem, and network perimeter security has to be audited as one.
Verizon's 2026 Data Breach Investigations Report puts a number on how widespread this pattern has become: 31% of breaches now start with software vulnerabilities, ahead of stolen passwords as the single most common way in, and 48% of all breaches now involve ransomware somewhere in the chain. Buyers asking about firewall security services are not buying a box that blocks bad traffic any more. They are buying a standing habit of checking what a patch did and did not fix.
We patched it fast
Our team shipped a fix within hours of disclosure, keeping customers protected against the latest threat.
We closed the whole gap
We force session invalidation and full credential rotation as standard procedure after every patch, not as an afterthought a customer has to request.
What Security Vendors Should Say Instead#
Here is where this stops being only a technical story and starts being a messaging one, which is the part folkfox actually gets paid to think about. Every vendor named in F5's bulletin ended up recommending the same four things: terminate sessions, rotate credentials, enforce MFA, upgrade to a version that fixes the underlying hash weakness. That is a genuinely differentiated claim sitting in plain sight, and almost nobody says it out loud in their own marketing.
'We patched it' is a sentence every competitor can say. 'We force session invalidation and credential rotation as standard procedure, not an afterthought' is a sentence only the vendors actually doing it can say, specific and provable and free of the sort of unliftable superlative buyers have learned to tune out. The goal is not just to patch the hole. It is to outfox the pattern these three vendors all fell into, and say so, specifically, as part of a genuine network perimeter security offer rather than a footnote.
Apply the vendor fix immediately. This closes the door but proves nothing about what already walked through it.
Force logout on all active user and administrator sessions on the affected device, invalidating anything an attacker copied before the patch.
Reset passwords for every account that authenticated through or is stored on the device, including service accounts nobody remembers exist.
A single account without multi-factor authentication was the entire gap in the SonicWall intrusion. Close that gap on every account, not just the sensitive ones.
Confirm the fix actually held with a vulnerability assessment rather than trusting the patch notes alone.
| Vendor | What was exploited | What the patch alone missed |
|---|---|---|
| Citrix NetScaler | CitrixBleed 2 (CVE-2025-5777), used by the Anubis ransomware group against Fairlife | Session tokens harvested before the patch stayed valid after it |
| SonicWall | A credential spray against an SSL VPN account with no MFA, leading to Akira ransomware | Multi-factor authentication on a single account, not a software flaw at all |
| Fortinet FortiGate | Reused credentials from earlier incidents, still valid after a firmware upgrade | Legacy SHA-256 password hashes the upgrade does not migrate to PBKDF2 |
None of this requires a rebuild. It requires a vendor willing to say, in its own content marketing and its own brand positioning, exactly what it does after a patch ships rather than just that a patch shipped. For MSSPs and security vendors selling into FinTech or healthcare, where a breach carries regulatory weight as well as reputational cost, that specificity is not a nice-to-have, it is the entire pitch. If your team already runs incident response or advises on vulnerability management, this week's bulletin is free proof for a pitch you were already trying to make. Track the pattern, not just the patch, and the next bulletin becomes a marketing asset instead of a fresh worry.
Frequently asked questions#
What does network perimeter security mean now that patches alone are not enough?
Network perimeter security used to mean a firewall rule and a login prompt. Three August 2026 incidents (CitrixBleed 2, SonicWall's Akira intrusion and Fortinet's firmware gap) show it now has to include session termination and credential rotation after every patch, because a patch fixes the software without touching what an attacker already copied.
What is CitrixBleed 2 and does patching fix it completely?
CitrixBleed 2 (CVE-2025-5777) is a memory disclosure flaw in Citrix NetScaler that can expose live session tokens. Patching closes the flaw itself, but F5 Labs confirms it does not invalidate session tokens or credentials an attacker already harvested, which is why teams also need to force session termination and password rotation.
How much does a vulnerability assessment cost?
Cost varies with scope: a single external-facing appliance is far cheaper to assess than a full network perimeter security review. The more useful question is what it buys, which is independent proof that a patch actually closed the gap rather than trusting the vendor's release notes alone.
What should firewall security services include beyond blocking traffic?
Modern firewall security services should include post-patch session termination, credential rotation and MFA verification as standard, not optional add-ons. Verizon's 2026 Data Breach Investigations Report found 31% of breaches now start with software vulnerabilities, so treating a firewall as a set-and-forget box is no longer defensible.
What counts as edge device security beyond a firmware update?
Edge device security now means auditing what a firmware update did not fix: old password hash formats, stale sessions, and credentials from earlier incidents that are still technically valid. Fortinet's own PSIRT blog confirms a firmware upgrade alone does not migrate legacy SHA-256 hashes to PBKDF2.
Does multi-factor authentication stop credential-spray attacks like the SonicWall breach?
In the SonicWall intrusion F5 Labs reported, the compromised account had no MFA at all, and that single gap let a routine credential spray become a domain-wide compromise within two hours. MFA does not stop every attack, but its absence was the entire opening this one needed, which is why any serious network perimeter security programme treats it as non-negotiable.
Read more on this topic#
Incident Response Services Now Have to Prove They Are Real
Why buyers now judge incident response on proof, not promises, before they hire a firm.
Read the pieceNobody Exploited a Single Flaw. They Just Used the Password
Another breach with no clever exploit at all, just a password nobody rotated in time.
Read the piecePatch Tuesday, Exploited Wednesday: What Vulnerability Management Services Must Prove Now
Five CVEs that went from patch to exploit in days, and what that means for remediation speed.
Read the pieceNIS2 Compliance Arrives One Day After Brussels Sued for the Wait
The regulatory side of the same story: what changes once incident response becomes a legal deadline.
Read the piece
Ready to prove your patch was actually a fix?
folkfox helps security vendors and MSSPs turn honest, specific remediation claims like session termination and credential rotation into marketing buyers actually believe.