Vulnerabilities · 65 days ago

Federal Buying Power Turns Against Legacy VPNs

This is turning remote access into a procurement problem, not just a patching problem. Wyden wants CISA, OMB, and NIST to push agencies off legacy public-facing VPNs and make zero-trust attestations a condition for buying remote-access gear, which would make older VPNs harder to justify even when they are technically patched.

The letter calls out internet-facing VPNs as a public front door and says federal agencies and contractors keep getting hit through that model. It points to past incidents across Cisco, Fortinet, Ivanti, and Check Point, and argues that emergency patch cycles keep failing because the architecture itself keeps exposing the entry point.

If this moves forward, vendors that cannot meet zero-trust procurement language could be pushed out of federal deals, and agencies may be forced to replace the access model rather than keep defending it. The pressure would come from contract rules and eligibility, not from a new exploit.

Timeline

Sources

2 sources covering this story

Vendor digest: Cisco

Vendor digest: Fortinet

Vendor digest: Ivanti

Part of the PlainSec briefing for 2026-07-28

Editions

Related stories