All Posts
8 min
min read
September 25, 2026
Exploited vulnerabilities at BeyondTrust, Palo Alto, Fortinet & Delinea: Why critical infrastructure now needs a European alternative.

US dependency in IT security is no longer an abstract debate, but a documented operational risk. The very products meant to guard the gateway to your IT—firewalls, VPN gateways, remote access, and privileged access solutions—have repeatedly become the entry point themselves at major US providers over the past two years: from the attack on the US Treasury to the BeyondTrust cloud and actively exploited zero-days at Palo Alto Networks and Fortinet.
This article reviews the documented incidents, explains why "platform consolidation" exacerbates the problem rather than solving it, and shows how VISULOX, as a German-Swiss solution with references in energy, telecommunications, and healthcare, brings control over the gateway back to Europe.
Key Takeaways
Firewalls, VPN gateways, remote support, and privileged access management solutions have one thing in common: by definition, they sit at the edge of the network, are accessible from the internet, and hold the keys to everything behind them. This is precisely why attackers—including state-sponsored groups—have shifted their priorities. Instead of phishing individual workstations, they are compromising the gateway itself.
The incident records of major US vendors from 2024 and 2025 prove this. The following cases are not assessments, but publicly documented facts—confirmed by the manufacturers themselves, the US Cybersecurity and Infrastructure Security Agency (CISA), and independent security researchers.

In late December 2024, it was revealed that attackers had breached the US Department of the Treasury via BeyondTrust’s cloud-based remote support solution. They captured a service API key and exploited two zero-day vulnerabilities (CVE-2024-12356, CVSS 9.8, and CVE-2024-12686) to access the agency's workstations and documents. The attack was attributed to a state-sponsored group. In June 2025, another critical vulnerability, CVE-2025-5309, followed in Remote Support and Privileged Remote Access, which could be exploited without authentication. We have analyzed the details in our article VISULOX as a German alternative to BeyondTrust .
In April 2024, Palo Alto Networks reported CVE-2024-3400 , a vulnerability of the highest possible criticality (CVSS 10.0) in the PAN-OS GlobalProtect gateway: unauthenticated code execution with root privileges, which had been actively exploited for weeks prior to disclosure. Security researchers identified over 82,000 vulnerable firewalls worldwide. Just seven months later, the next chapter unfolded: the combination of CVE-2024-0012 and CVE-2024-9474 allowed for the complete takeover of the management interface in November 2024; approximately 2,000 compromised devices were counted before patches were applied.
Fortinet began 2025 with a double incident: in January, the actively exploited authentication bypass vulnerability CVE-2024-55591 in FortiOS was disclosed, granting attackers super-admin rights on FortiGate firewalls. Almost simultaneously, a group known as the "Belsen Group" published the full configurations and VPN credentials of approximately 15,000 FortiGate firewalls—captured via a vulnerability dating back to 2022. In November 2025, CVE-2025-64446 in FortiWeb (CVSS 9.8) followed: attackers used the zero-day to automatically create their own administrator accounts on exposed systems; CISA set a patch deadline of November 21, 2025.
In April 2024, Delinea had to urgently patch a critical vulnerability in the Secret Server SOAP API—the very component that stores corporate secrets and privileged credentials. The flaw allowed for a complete authentication bypass, leading to administrator privileges. The sequence of events was notable: the security researcher had attempted to report the flaw in February but was turned away because they were not a paying customer—eventually going public before the manufacturer had released a patch.
Every software has vulnerabilities – including European ones. The difference lies in what is added to the technical attack surface: the legal framework. All four mentioned providers are US companies and are therefore subject to the US CLOUD Act, which obliges them to hand over data upon the order of US authorities – regardless of whether it is stored in Virginia or Frankfurt. For access and session data from your IT gateway, this is no mere footnote: it is the most sensitive metadata an organization produces. We have broken down the resulting criteria for choosing a provider in our guide Sovereign PAM Solution: 7 Criteria .
Added to this is the geopolitical dimension: export controls, sanctions regimes, and political volatility in the US can affect licenses, updates, and support contracts – factors that no CISO can control, but which determine the availability of their own security infrastructure.
The major providers' answer to their own complexity is "platform consolidation": firewall, VPN, access management, and monitoring from a single source, with bundle discounts as an entry incentive. In the short term, this seems efficient. In the medium term, it creates a concentration risk with three dimensions:
Best-of-breed with clear interfaces is not a step backward, but risk diversification. The most sensitive layer in particular – privileged access – does not belong in the same bundle as the rest of the stack, but under your own control.
VISULOX is the remote privileged access management solution from amitego AG, a German-Swiss IT security manufacturer: product development and support for over 20 years in Stuttgart, sales & service for Europe in Zurich, and additional development in Laax. There is no US parent company, no non-European ownership structure, and no CLOUD Act leverage. The solution runs entirely on-premises and is implemented agentlessly – often in under two days – and bundles internal and external privileged access via a central access point with multi-factor authentication, just-in-time approvals, and audit-proof session recording.
The key point is: this is not a niche promise, but a proven solution in critical infrastructure. Our publicly documented references include energy providers like RWE Power and transmission system operator Thyssengas, telecommunications groups like Vodafone Group, healthcare and pharmaceutical companies like Merck, and hospital networks – environments where secure remote maintenance of OT and clinical systems must function reliably every single day. Over 450 IT teams in more than 20 countries work with VISULOX.
For the requirements of NIS-2 (§ 30 BSIG), ISO 27001, and Art. 32 GDPR, the following applies: Verifiable control of privileged access is mandatory – the legal jurisdiction where these records are kept is your choice. See how a transition pays off with our price and license calculator in just a few minutes.
It combines two levels of risk: technically, the documented, repeatedly exploited vulnerabilities in exposed US security products (BeyondTrust, Palo Alto Networks, Fortinet, Delinea, 2024–2025); and legally, the US CLOUD Act, which compels US providers to hand over data to US authorities regardless of where the server is located.
No. The CLOUD Act applies to the company, not the storage location. A US provider with a data center in Frankfurt remains subject to disclosure requirements. The decisive factors are the provider's legal jurisdiction and ownership structure.
In the short term, yes, but in the long term, it creates vendor lock-in: a vulnerability in the platform core affects all functions simultaneously, switching costs rise with every bundled component, and the provider gains pricing power. Risk diversification via a best-of-breed approach with clear interfaces is the more robust strategy.
Yes. VISULOX by amitego has been developed and operated in Germany and Switzerland for over 20 years, runs on-premises, and is used by organizations including RWE Power, Thyssengas, the Vodafone Group, and Merck—as documented in public case studies.
Contact
Speak directly with a cybersecurity expert.
The years 2024 and 2025 have revealed a pattern: the products at the IT gateway—from US market leaders like BeyondTrust, Palo Alto Networks, Fortinet, and Delinea—have repeatedly become the entry point themselves, while the CLOUD Act additionally subjects access data to a foreign legal jurisdiction. Consolidating onto a US platform deepens this dependency instead of resolving it. VISULOX offers the sovereign alternative: developed in Germany and Switzerland, operated on-premises, and proven in Europe's most critical sectors—from energy and telecommunications to hospitals. Check your gateway before someone else does. (This article does not constitute legal advice.)
Table Of Content:
Talk to Our Experts
Speak directly with a VISULOX security expert and find out how to protect your infrastructure.
Share:
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Expert knowledge, practical tips, and the latest trends in PAM, compliance, and secure remote work — straight from the amitego team.