top of page

SSL VPN End of Life: Why Legacy Cisco ASA VPNs Are Now a Top Ransomware Target

  • 1 hour ago
  • 8 min read

SSL VPN End of Life

If your organization still hands remote employees a Cisco ASA, FortiGate, Ivanti Connect Secure, or Citrix NetScaler Gateway SSL VPN client, you're running one of the most actively exploited pieces of infrastructure in enterprise IT. Cisco, Fortinet, Ivanti, and Citrix have all shipped emergency patches for actively exploited vulnerabilities in their remote-access VPN appliances within the past eighteen months, and CISA has issued emergency directives ordering federal agencies to check for compromise. Combined with hard vendor deadlines pushing SSL VPN end of life on aging hardware, the case for a Cisco ASA VPN replacement — and for a broader plan to replace legacy VPN altogether — has moved from an IT roadmap item to a board-level risk conversation.


Key takeaways


  • SSL VPN appliances from Cisco, Fortinet, Ivanti, and Citrix have each had actively exploited, CISA-flagged vulnerabilities disclosed in 2025 and 2026, making remote-access VPN gateways one of the most targeted categories of edge device in enterprise networks.

  • The Verizon 2026 Data Breach Investigations Report found that vulnerability exploitation overtook stolen credentials as the top breach vector for the first time in 19 years, driven largely by unpatched internet-facing appliances.

  • Cisco's ASA 5500-X hardware line exits support on a rolling schedule between September 2025 and August 2026, and Ivanti's Connect Secure line carries its own history of emergency patches — meaning "patch and wait" is running out as an option for a large share of installed VPN hardware.

  • Ransomware crews, including the Akira group, have used SSL VPN flaws — in one case a suspected SonicWall zero-day — to move from initial access to full encryption in under an hour.

  • ZTNA and SASE replace the network-level VPN tunnel with per-application, identity-verified access, closing the exposure behind these advisories — Zscaler, Cloudflare, Palo Alto Networks, Netskope, and Cisco are the vendors most consistently named as leaders.


Why SSL VPN appliances became a top ransomware target


Remote-access SSL VPN and IPsec appliances sit in a uniquely bad spot: they're internet-facing by design, they grant broad network access once a session is authenticated, and they're often treated as "set it and forget it" infrastructure that runs outdated firmware longer than almost anything else on the network. That combination has made them a favorite target for both opportunistic ransomware crews and more patient intrusion sets over the past two years.


The pattern is consistent across nearly every major VPN vendor:


  • Cisco. In September 2025, Cisco disclosed two actively exploited flaws in ASA and Firepower software — CVE-2025-20333, a remote code execution bug in the VPN web server, plus a companion unauthorized-access flaw. CISA responded with Emergency Directive 25-03, ordering federal agencies to inventory every ASA/Firepower device and submit forensic memory captures within 24 hours, and urged private-sector organizations to do the same.

  • Ivanti. CISA and international partners issued two joint advisories on Ivanti Connect Secure and Policy Secure gateways — AA24-060B (2024) and AA25-022A (2025) — describing threat actors chaining vulnerabilities to gain persistent, unauthenticated access to gateway appliances.

  • Fortinet. In January 2026, CISA published guidance on CVE-2026-24858, a FortiOS SSO authentication bypass under active exploitation, following a December 2025 warning about an actively exploited two-factor authentication bypass in FortiOS SSL-VPN.

  • Citrix. The "CitrixBleed 2" flaw in NetScaler ADC and Gateway, CVE-2025-5777, let attackers hijack authenticated sessions by leaking appliance memory. A follow-on critical flaw, CVE-2025-7775, was confirmed exploited within days of disclosure.


The pattern says more about the architecture than any one vendor: an appliance that terminates VPN sessions on the public internet and grants broad network access after one authentication event is a high-value target, and attackers now weaponize new VPN CVEs within hours of disclosure.


The ransomware angle: VPN gateways are the front door


Remote-access VPN exploitation isn't a theoretical risk — it's a documented ransomware delivery mechanism. In August 2025, the Akira ransomware group ran an aggressive campaign against SonicWall SSL VPN devices, compromising fully patched appliances in what researchers suspected was a zero-day, and moving from initial access to ransomware deployment in as little as an hour. CISA's own #StopRansomware advisory on Akira documents the group's broader pattern of exploiting VPN and edge-device vulnerabilities for initial access.


That's consistent with the macro trend. The 2026 Verizon DBIR found vulnerability exploitation surpassed stolen credentials as the top initial access vector for the first time in the report's 19-year history — and only 26% of CISA's Known Exploited Vulnerabilities were fully remediated by surveyed organizations, down from 38% the year before, with median time-to-patch stretching to 43 days.


Sophos's 2026 State of Ransomware report adds a useful nuance: exploited vulnerabilities dropped to 18% of reported ransomware root causes, down from roughly 32% the prior year, as identity-based attacks — phishing, malicious email, and compromised credentials — climbed to a combined 73%. But that doesn't make VPN exploitation less urgent; it just changes the mechanism. CitrixBleed-style session hijacking and Ivanti credential harvesting are, in effect, identity attacks that start with a VPN appliance vulnerability.


SSL VPN end of life is arriving on a fixed schedule


Cisco ASA hardware sunset


Cisco's ASA 5500-X series firewalls — long the default appliance for Cisco ASA VPN deployments — are exiting support in stages. The 5525-X, 5545-X, and 5555-X models reached end-of-support on September 30, 2025, and the 5506-X, 5508-X, 5515-X, and 5516-X models follow on August 31, 2026. After each date, that hardware stops receiving security fixes entirely — including for whatever the next actively exploited VPN web server flaw turns out to be.


Ivanti and the broader legacy VPN fleet


Ivanti's Connect Secure and Policy Secure lines (formerly sold as Pulse Secure) have been the subject of repeated CISA advisories, and Fortinet's and Citrix's remote-access products keep receiving patches on a near-monthly cadence. Even where a vendor ships updates promptly, most mid-market IT teams can't patch fast enough to stay ahead of the 24-to-48-hour exploitation window the Verizon and CISA data above describes. SSL VPN end of life isn't one event — it's a rolling set of hardware deadlines and exploitation windows that compound each other, and the realistic fix isn't a faster patch cadence on the same architecture; it's replacing the architecture.


What actually changes with ZTNA vs. traditional VPN


Traditional remote-access VPN — SSL VPN or IPsec — does one thing: it extends your internal network to a remote device. Once authenticated, the user's laptop effectively becomes a node on your LAN, with a routable path to whatever the VPN profile permits, which in many organizations is most of the network. That's why VPN compromises escalate so fast: the appliance is a single, internet-facing chokepoint that, once breached, hands an attacker broad lateral access.


Zero Trust Network Access works differently in three specific ways:


  • No inbound listening port. A ZTNA connector makes an outbound-only connection to a cloud broker, so there's no gateway sitting on the public internet with an open port to scan — the exact exposure behind the advisories above.

  • Per-application access, not network-level access. Users get access to specific applications they're authorized for, not a routable path onto the broader network, so a compromised credential can't be used to pivot laterally the way a compromised VPN session can.

  • Continuous verification, not one-time authentication. ZTNA evaluates identity, device posture, and context on an ongoing basis rather than trusting a session indefinitely after login, limiting the damage of a stolen session token — the same technique CitrixBleed relied on.


SASE: the architecture ZTNA lives inside


ZTNA is the access-control piece; Secure Access Service Edge (SASE) is the broader architecture that wraps ZTNA together with a cloud secure web gateway, cloud access security broker, and firewall-as-a-service, delivered as a single cloud-native platform instead of a rack of separate on-premises boxes. For organizations retiring legacy VPN, this matters practically: instead of swapping one aging VPN concentrator for a newer one, most mid-market buyers are consolidating remote access, web filtering, and cloud app security into a single converged service — removing another category of hardware that would otherwise need its own future end-of-life clock.


The realistic vendor landscape for SASE and ZTNA


Palo Alto Networks, Netskope, and Zscaler were named leaders in the 2025 Gartner Magic Quadrant for Security Service Edge, and Fortinet joined that leader group alongside Cato Networks in the 2025 SASE Magic Quadrant. For a mid-market buyer comparing options against a legacy VPN estate:


  • Zscaler Private Access. One of the earliest, most established ZTNA platforms, with deep application-level segmentation. Trade-off: it's built around a broader Zscaler platform commitment, and pricing rewards adopting the wider ecosystem rather than ZTNA alone.

  • Cloudflare Access (part of Cloudflare One). Positioned explicitly as a VPN replacement, with fast deployment and pricing that's often more approachable for smaller IT teams. Trade-off: some enterprise data-protection and CASB capabilities are less mature than the largest platform vendors.

  • Palo Alto Networks Prisma Access. A strong fit for organizations already standardized on Palo Alto firewalls, with tight integration between network security and ZTNA policy. Trade-off: it's a premium, feature-dense platform that can exceed what a lean IT team needs day to day.

  • Cisco Secure Access (built on Duo). A natural migration path for organizations already running Cisco networking and Duo MFA, with a clear upgrade story for shops retiring an ASA-based VPN. Trade-off: as a newer SASE entrant, feature breadth still trails Zscaler and Palo Alto in some areas.


Netskope, Fortinet's FortiSASE, and Cato Networks are also credible options worth evaluating depending on existing vendor relationships, which is exactly the kind of comparison a vendor-agnostic advisory process is built to run objectively rather than through a single vendor's sales motion.


A practical migration path off legacy VPN


Retiring a legacy VPN estate doesn't have to mean a disruptive, all-at-once cutover. A phased approach limits risk on both sides — security exposure and operational disruption.


  • Inventory and triage. Catalog every VPN appliance, firmware version, and support end date, then cross-reference against CISA's Known Exploited Vulnerabilities catalog to prioritize which gateways to replace first.

  • Pilot ZTNA with a high-risk user group first. Start with privileged users, contractors, or third parties — the accounts that would do the most damage if compromised — rather than rolling out to the whole company on day one.

  • Migrate application by application, not user by user. Move access to specific high-value applications behind the ZTNA broker while leaving lower-risk legacy VPN access in place temporarily.

  • Decommission the VPN appliance last, not first. Keep the legacy gateway patched and monitored until the ZTNA/SASE platform is carrying production traffic reliably, then formally retire it rather than leaving it running unmanaged "just in case."

  • Re-evaluate connectivity and network architecture at the same time. SASE adoption often overlaps with SD-WAN decisions, so review connectivity and network solutions alongside the security migration rather than as a separate project.


Frequently asked questions


Is my organization actually at risk if we haven't been named in a specific breach?


Yes. CISA's advisories on Cisco, Ivanti, Fortinet, and Citrix VPN products describe mass, opportunistic scanning and exploitation, not targeted attacks on named victims — any internet-facing appliance running a vulnerable version is a target regardless of company size.


Do we need to rip out our VPN and deploy SASE on day one?


No. Most organizations run legacy VPN and a new ZTNA/SASE platform side by side, moving applications and user groups over in stages rather than cutting over everything at once.


Is ZTNA only for large enterprises?


No. Several ZTNA and SASE platforms are packaged and priced for mid-market organizations, and cloud delivery removes much of the hardware burden that made legacy VPN expensive to run at smaller scale.


Does moving to SASE eliminate the need for on-premises network security entirely?


Not necessarily. Many organizations keep some on-premises security for local traffic while shifting remote access and cloud app traffic to the SASE platform; the right mix depends on your architecture and is worth reviewing with a qualified advisor.


How urgent is this compared to other IT priorities?


Given active CISA emergency directives, documented ransomware campaigns exploiting VPN appliances, and vendor end-of-support dates already in effect for some ASA hardware, this belongs on the same priority tier as other actively exploited, internet-facing risks.


The bottom line


Legacy SSL VPN and IPsec remote-access appliances have gone from a mature, low-drama category of IT infrastructure to one of the most actively exploited attack surfaces in enterprise networks, and the vendor deadlines behind SSL VPN end of life mean the exposure window isn't closing on its own. A Cisco ASA VPN replacement, or an equivalent move off Fortinet, Ivanti, or Citrix SSL VPN, is no longer a modernization nice-to-have — it's a documented ransomware risk with real advisories and real deadlines attached to it.


The right architecture and vendor mix depends on your network, risk profile, and which platforms your team can realistically operate, which is exactly the kind of comparison AGI Beacon's vendor-agnostic advisory model is built to support rather than a single vendor's pitch. If you're ready to compare SASE and ZTNA options against your current VPN footprint, connect with a vetted provider through AGI Beacon for a side-by-side, no-pressure comparison built around your environment.


 
 
 

Comments


bottom of page