Your Firewall Might Be the Hole: Why “Supported” Is the Hardest Hardening Move You Will Make This Year
On February 5, 2026, CISA issued Binding Operational Directive 26-02 with a deadline you can set your calendar by. Federal civilian agencies now have **90 days** to inventory every edge device running end-of-support software, **12 months** to either update or replace it, and **18 months** to remove anything that still cannot be brought back into support. Edge means the boxes most IT teams forget they own: firewalls, VPN gateways, load balancers, switches, wireless controllers, the small routers stuffed in wiring closets. The directive applies to the federal government. The reasoning applies to every small and midsize business running the same equipment.
The reason the directive exists is that attackers are eating end-of-support devices alive, and most organizations do not know which boxes in their environment have stopped receiving updates. That single fact is the hardening problem of 2026.
The Backlog Nobody Is Looking At
CISA’s accompanying guidance is blunt: nation-state actors actively exploit end-of-support edge devices because they sit at the network perimeter, hold privileged access, and are not getting patched. The interesting part is how they got there. Cisco’s own end-of-life hub notes that 32% of the devices still being hit by old exploits are more than a decade old. SonicWall’s 2026 Cyber Protect Report found ransomware in **88% of SMB breaches**, with an average dwell time of **181 days** before detection. Large enterprises logged a 39% ransomware rate. The small business gap is not closing. It is widening.
The SonicWall number deserves a second read. It is not that SMBs are getting attacked more. It is that the attacks that do land are more likely to become ransomware, because the path in is older, flatter, and quieter. A 2014 ASA sitting in a branch office, a FortiGate whose support contract lapsed in 2023, a SonicWall TZ series whose owner did not get the end-of-life email. Each one is a door someone forgot to lock.
The CVEs Are the Easy Part
The harder problem is not the patches. It is knowing what to patch. Recent edge CVEs show the speed of the cycle, and they are not kind to unsupported gear:
– **CVE-2026-20316** in Cisco Secure Firewall Management Center: static credentials for a built-in account, disclosed in July 2026, actively exploited. Interlock ransomware affiliates are using it. – **CVE-2026-15409 and CVE-2026-15410** in SonicWall firewalls, chained together to land INC ransomware on small businesses. Security AI researchers caught them being used in the wild before the disclosure date. – **FortiBleed-class** issues across FortiGate SSL VPN, with over 70,000 Fortinet firewalls compromised across the wave, mostly through credential harvesting from devices still running firmware the vendor had stopped updating.
Every one of these had a vendor patch. Every one of them required the device to still be in support for the patch to actually be available. The devices that were not in support did not get a fix. They got removed.

Why End-of-Support Hides
The reason this category of risk hides is structural. End-of-support is a vendor decision, not a security decision. The manufacturer publishes a date. Resellers stop stocking replacements. Sales teams stop quoting renewals. The IT team inherits a device that is still working, still handling traffic, still on the network diagram, but is no longer on anyone’s roadmap. The vulnerability scanner misses it because it does not know the support contract lapsed. The EDR has no agent on it. The patch report comes back empty because there are no patches to apply.
Three things cause this:
– **Procurement by renewal inertia.** A firewall bought in 2018 with a three-year support contract became unsupported in 2021. The replacement budget cycle was 2020. The device was not on the radar when the budget was set, so it kept running. – **Acquired devices on someone else’s schedule.** When a company acquires another company, or inherits a contractor’s handiwork, the edge devices come along without their history. The new owner has no record of the support status, no idea which firmware is current, and no relationship with the original vendor. – **Branch-office drift.** A regional office got its own firewall in 2017. The local IT generalist set it up. The corporate IT team never touched it. Five years later, it is still doing its job. Nobody asked the question.
What the Federal Mandate Actually Means for SMBs
BOD 26-02 does not apply to private businesses. The 90-day, 12-month, and 18-month timelines are for federal agencies. But the operational steps are exactly what an SMB needs to do, because the threat picture is the same. Three moves:
**Run an edge inventory by next Friday.** Not a sit-down meeting, an inventory. Pull a list of every firewall, VPN gateway, router, switch, and wireless controller in your environment. For each one, record the make, model, firmware version, and support status. CISA publishes a free tool to query Cisco, Fortinet, Palo Alto, and Juniper support status. For anything else, the vendor support page is the source of truth. If a device is past its support date, it goes on the replacement list. If you do not know its support status, that is the same as it being past support.
**Decide replace, not patch.** If a device is out of support, you cannot patch it. The hardening move is replacement. For a small business running a single firewall at HQ and one at the branch, this is a three-month project, not a three-year one. The federal 12-month timeline is generous for an SMB.
**Lock the configuration on supported devices.** CISA’s edge-device guidance from 2025, led jointly with the NSA, the ACSC, the CCCS, and the NCSC-UK, lays out seven mitigations. The two that pay off the fastest for small teams: disable management from the public internet, and require a dedicated admin workstation on a separate management network for any configuration work. If the only way to log into your firewall is from a specific laptop on a specific VLAN, a stolen VPN credential does not give an attacker the keys to the perimeter.
The Uncomfortable Trade
The honest part of this conversation is the budget conversation. Replacing a fleet of edge devices is not free. For a shop running five to ten firewalls on three-year refresh cycles, the cost is real, and it shows up in the same quarter as the AI tooling bill and the cyber insurance premium. Most small businesses will defer it.
That is the wrong call this year. The SonicWall 88% number, the 181-day dwell time, and the wave of edge CVEs in 2026 are the same story told three ways: the attacker is coming through old, forgotten, unmonitored boxes at the network edge, and the SMB is the one paying the ransom.
Pick one device. Pick the one that has been there the longest. Replace it this quarter. Then pick the next one. A 20% replacement a quarter gets the whole fleet off the end-of-support list in five quarters. That is faster than the federal government has to do it.
