Ness City Computer Service LLC

Home › Blog › Security
Security

VPN and Remote-Access Gateways Are Under Attack: Questions to Ask Your IT Provider

By Chris Harrison · October 8, 2026 · 5 min read

The device that lets your team work from home is also the front door of your network. That is why attackers love it, and why September 2026 was a rough month for remote-access and network security equipment.

What was attacked

  • Citrix NetScaler ADC and Gateway: two critical flaws that let attackers run commands on the device without logging in. Researchers say they were exploited for weeks before a fix was available, and attackers planted hidden “web shells” and tried to erase their tracks.
  • Cisco Identity Services Engine (ISE): a maximum-severity (10 out of 10) flaw that lets an attacker bypass the login, actively exploited.
  • F5 BIG-IP Access Policy Manager, two Check Point flaws and Arista VeloCloud Orchestrator: all added to CISA’s list of actively exploited vulnerabilities on September 22.

Does this affect a small Kansas business?

Most small businesses don’t own these specific enterprise products. But you may depend on someone who does: a hospital, bank, software vendor or your corporate parent. And the lesson applies to every VPN and firewall, including the SonicWall, pfSense and similar devices common in small offices.

Five questions to ask whoever manages your network

  1. Is our firewall/VPN firmware current, and when was it last updated?
  2. Is multi-factor authentication required for every remote login? A stolen password alone should never be enough.
  3. Is the management page reachable from the internet? It shouldn’t be.
  4. Who gets the security alerts for this device, and how fast do they act?
  5. If a third party runs our remote access, can they confirm in writing that it’s patched?

Patched isn’t the same as safe

Several of these attacks left backdoors behind, and a well-equipped attacker can delete the device’s own logs. That is why investigators recommend saving logs before updating and checking for signs of compromise afterward. If a vulnerable device was exposed to the internet, treat it as a possible break-in, not just a missing update.

Want a second set of eyes?

We will review your firewall, VPN and remote-access setup and tell you in plain English what’s solid and what’s risky. Call us at 620-960-8711 or request a free network assessment. Learn about our managed cybersecurity.

Sources: Help Net Security: Citrix NetScaler zero-days · Help Net Security: Cisco ISE · Security Arsenal: CISA KEV, Sept. 22

Want more free guides like this? Browse our Scam & Security Library — real examples of phishing emails, scam texts, fake pop-ups and more.

Chris Harrison, owner of Ness City Computer Service
About the author
Chris Harrison

Chris owns Ness City Computer Service and has more than 30 years of IT experience helping Kansas homes and businesses keep their technology running and secure.

Have a question about your tech?

Call the local guys. We’re happy to help — no pressure.

Services

How we can help

Computer repair & PC sales

Managed IT services

Cybersecurity

Networking & Wi-Fi

Backup & disaster recovery

VoIP business phones

Surveillance & alarms

Web design & hosting

Scroll to Top