Article Details

Scrape Timestamp (UTC): 2026-02-06 13:50:08.124

Source: https://thehackernews.com/2026/02/cisa-orders-removal-of-unsupported-edge.html

Original Article Text

Click to Toggle View

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered Federal Civilian Executive Branch (FCEB) agencies to strengthen asset lifecycle management for edge network devices and remove those that no longer receive security updates from original equipment manufacturers (OEMs) over the next 12 to 18 months. The agency said the move is to drive down technical debt and minimize the risk of compromise, as state-sponsored threat actors turn such devices as a preferred access pathway for breaking into target networks. Edge devices is an umbrella term that encompasses load balancers, firewalls, routers, switches, wireless access points, network security appliances, Internet of Things (IoT) edge devices, software-defined networks, and other physical or virtual networking components that route network traffic and hold privileged access. "Persistent cyber threat actors are increasingly exploiting unsupported edge devices -- hardware and software that no longer receive vendor updates to firmware or other security patches," CISA said. "Positioned at the network perimeter, these devices are especially vulnerable to persistent cyber threat actors exploiting a new or known vulnerability." To assist FCEB agencies in this regard, CISA said it has developed an end-of-support edge device list that acts as a preliminary repository with information about devices that have already reached end-of-support or are expected to lose support. This list will include the product name, version number, and end-of-support date. The newly issued Binding Operational Directive 26-02, Mitigating Risk From End-of-Support Edge Devices, requires FCEB agencies to undertake the following actions - "Unsupported devices pose a serious risk to federal systems and should never remain on enterprise networks," said CISA Acting Director Madhu Gottumukkala. "By proactively managing asset lifecycles and removing end-of-support technology, we can collectively strengthen resilience and protect the global digital ecosystem."

Daily Brief Summary

VULNERABILITIES // CISA Mandates Removal of Unsupported Edge Devices to Mitigate Risks

CISA has instructed Federal Civilian Executive Branch agencies to eliminate unsupported edge devices within 12 to 18 months to minimize security risks.

Edge devices, including routers, firewalls, and IoT components, are often targeted by state-sponsored actors due to their network perimeter positioning.

Unsupported devices are vulnerable to exploitation as they no longer receive security updates, posing significant risks to federal networks.

CISA has created an end-of-support edge device list, detailing devices that have or will soon lose OEM support, aiding agencies in compliance efforts.

The directive aims to reduce technical debt and enhance federal network resilience by enforcing proactive asset lifecycle management.

This initiative reflects a broader strategy to safeguard the digital ecosystem against persistent cyber threats by addressing vulnerabilities in critical infrastructure.