Security

A zero-day just hit your router or VPN. Do these 7 things today

(today) · 3 min read · By Future Technology

Key takeaways

  • Confirm the exact product and version are exposed before doing anything else.
  • Patch or apply the vendor mitigation, then assume the device may already have been touched.
  • Pull admin interfaces off the public internet and rotate every credential the device holds.
  • Check logs from weeks before the disclosure date, not just from today.

Two network-edge zero-days in one week. Cisco's SD-WAN authentication bypass (CVE-2026-76504) and a FortiMail flaw were both being exploited before most admins had read the advisories, and we covered them in the Cisco SD-WAN bug and the FortiMail zero-day. The product changes every week, but what to do after a zero-day should not.

This checklist is for the gear that sits between your network and the internet: routers, firewalls, VPN concentrators and email gateways. It works for a two-person office and scales up to a proper IT team.

1. Confirm you are actually exposed

Start with the advisory, not the headline. Note the exact product names and affected versions, then check what you run. A zero-day in one product line often leaves its sister products alone, and an hour spent patching the wrong box is an hour the right one stays open.

2. Check whether it is already being exploited

If the bug appears in CISA's Known Exploited Vulnerabilities catalog, treat it as urgent wherever you are based. It is a US government list, but it is the fastest public signal that attackers are using a flaw in the wild. Our guide to checking the CISA KEV catalog walks through it.

3. Patch, or apply the mitigation

Install the fixed version if one exists. If the vendor has only published a workaround, apply it now and schedule the real patch. Vendors post both on their own pages, such as Cisco's security advisories and Fortinet's PSIRT, and those pages update faster than news coverage does.

4. Take admin interfaces off the internet

Many edge-device zero-days need access to the admin login page. If yours can be reached from the public internet, restrict it to a VPN or a short list of trusted IP addresses. To see what the outside world can reach, follow our walkthrough on checking if your server is exposed to the internet.

5. Assume compromise and rotate credentials

A patch closes the door, but it does not remove anyone who came in first. Change admin passwords on the device, rotate any API keys or service accounts it stores, and reissue VPN certificates if it handles them. While you are there, put phishing-resistant multi-factor authentication on admin accounts. A hardware key such as the YubiKey 5 NFC is the simplest way to do that, and you can check current pricing on Amazon.

6. Read the logs from before the disclosure

Zero-days are used before the public knows about them, which is the whole definition. Look back at least a few weeks for unfamiliar admin logins, new user accounts, configuration changes and unexpected outbound connections. If the vendor publishes indicators of compromise, search for those specifically.

7. Subscribe so you hear first next time

Sign up for security advisories from every vendor whose kit sits on your network edge. Plain email alerts are fine. The goal is to read the advisory on day one rather than in a news story on day three.

The part worth sitting with

Edge devices keep turning up in exploited-bug lists because they face the internet by design and hold credentials, yet they rarely get watched as closely as laptops and servers. None of these seven steps needs special tools, only someone who knows the checklist exists before the next advisory drops.

*Some links in this article are affiliate links. We may earn a small commission at no extra cost to you.*

More from Future Technology