Skip to content
2026 GreyNoise State of the Edge Report: Where Attacks Concentrate and Defenses Fall Short

2026 GreyNoise State of the Edge Report: Where Attacks Concentrate and Defenses Fall Short

Greynoise • February 24, 2026

More than half of the most dangerous exploitation attempts hitting internet-facing infrastructure came from IPs with no prior history in GreyNoise data. GreyNoise analyzed 2.97 billion sessions over 162 days in H2 2025, and the pattern that emerged is clear: for remote code execution — the highest-severity exploitation category — GreyNoise had no prior record of more than half the attacking IPs, suggesting that scanning-history-based reputation alone may have structural coverage gaps for the most dangerous exploitation attempts.

Across the GreyNoise Global Observation Grid, several findings challenge conventional assumptions where attacks concentrate:

Palo Alto GlobalProtect received 16.7 million sessions — more than 3.5x Cisco and Fortinet combined. This disproportionate concentration warrants investigation, though direct market comparison was not part of this analysis. GlobalProtect deployments provide direct network access if compromised, making them high-value targets.

52% of remote code execution attempts came from IPs with no prior history in GreyNoise data. For remote code execution — widely considered the highest-severity exploitation category — GreyNoise had no prior record of more than half the attacking IPs.

Pre-2015 CVEs generated 7.3 million sessions — 4x more than 2023-2024 CVEs combined. One vulnerability — CVE-1999-0526, a 26-year-old X Server information disclosure — accounts for the majority. Even excluding it, Shellshock and PHP-CGI continue generating measurable traffic a decade later. Patching programs optimized for recency leave decade-old exposure unaddressed.

300,000 residential IPs participated in a single credential-spraying campaign — 73% classified as residential by ISP categorization, with no prior GreyNoise history. Geographic blocking, reputation scoring, rate limiting: would have limited effectiveness against this traffic pattern.

91,403 sessions targeted AI/LLM infrastructure. The same types of automated scanning patterns hitting VPNs and routers are now cataloging exposed LLM endpoints.

The Verizon 2025 DBIR documented an 8x increase in edge device exploitation in a single year — edge vulnerabilities jumped from 3% to 22% of all vulnerability exploitation breaches. Mandiant M-Trends 2025 found the top four most frequently exploited vulnerabilities were all in edge devices — Palo Alto PAN-OS, Ivanti Connect Secure, Ivanti Policy Secure, and Fortinet FortiClient EMS. CISA issued Binding Operational Directive 26-02, requiring federal agencies to address end-of-support edge devices. The GreyNoise data is consistent with all of it — and quantifies the scale.

This isn't a theoretical shift. If your organization runs internet-facing VPN appliances, routers, or AI infrastructure, this traffic is reaching you.

The full report includes: