Vulnerabilities · 65 days ago
This is turning remote access into a procurement problem, not just a patching problem. Wyden wants CISA, OMB, and NIST to push agencies off legacy public-facing VPNs and make zero-trust attestations a condition for buying remote-access gear, which would make older VPNs harder to justify even when they are technically patched.
The letter calls out internet-facing VPNs as a public front door and says federal agencies and contractors keep getting hit through that model. It points to past incidents across Cisco, Fortinet, Ivanti, and Check Point, and argues that emergency patch cycles keep failing because the architecture itself keeps exposing the entry point.
If this moves forward, vendors that cannot meet zero-trust procurement language could be pushed out of federal deals, and agencies may be forced to replace the access model rather than keep defending it. The pressure would come from contract rules and eligibility, not from a new exploit.
2 sources covering this story
The Record from Recorded Future
Outdated VPNs should be purged from federal agencies, senator says
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S.
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Ron Wyden urges CISA, OMB, and NIST to purge legacy VPNs across federal agencies and enforce zero-trust procurement standards.
Part of the PlainSec briefing for 2026-07-28