Industrialcyber.Co Forescout Report Reveals Rising Risks of Connected Devices in 2026
Article Content
- •Network infrastructure has surpassed endpoints as the highest-risk category in cybersecurity.
- •Routers account for one-third of critical vulnerabilities, averaging 32 vulnerabilities each.
- •11 new device types have been added to the riskiest category, reflecting a rapidly diversifying attack surface.
Forescout Technologies' '2026 Riskiest Connected Devices' report indicates a significant shift in cybersecurity risks, with network infrastructure now deemed the highest-risk category in IT environments. The report highlights that routers account for approximately one-third of critical vulnerabilities, with an average of 32 vulnerabilities per device. A total of 11 new device types have entered the riskiest category, marking the second-largest year-over-year increase on record. These devices, including serial-to-IP converters and medication dispensing systems, often operate with outdated firmware and default credentials, making them attractive targets for attackers. The report emphasizes the exploitation of east-west traffic, allowing adversaries to move laterally within networks. Organizations are increasingly connecting specialized and unmanaged devices, expanding the attack surface significantly. The report identifies three new entries targeting operational technology (OT) environments, including power distribution units (PDUs) and BACnet routers. Barry Mainz, CEO of Forescout, stresses the importance of containment as a modern cybersecurity strategy.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…