Tenable and SentinelOne Find Vendor-Level Repeat Pressure
Tenable and SentinelOne analyzed 93 CVE-actor pairs and found that state-backed and criminal groups keep showing up on the same edge-vendor families, with 79% overlap at the vendor level and 12 CVEs seen across more than one actor nexus.
The point is not that the same bugs are always reused. The datasets line up on products like F5, Fortinet, Citrix, Check Point, Ivanti, and Palo Alto Networks even when the CVEs differ, which means a CVE-by-CVE queue can miss how much repeat pressure lands on the same perimeter products.
For teams that run edge gateways, the exposure picture is now clustered around product families: one vendor line can remain a recurring entry point for different actor types after a specific flaw is fixed. The reporting does not settle how much of that pressure is active today versus just historically persistent.