16 September 2026 / 3 minutes of reading
Infrastructure projects were our second most common type of engagement in 2025. We tested 104 of them, accounting for approximately 17% of all projects. This was also where we encountered the highest number of severe findings across all areas: 74 critical and 125 high-severity vulnerabilities, representing an average of almost two critical or high-severity vulnerabilities per project.
At the same time, as many as 71% of infrastructure projects contained at least one critical vulnerability—the highest proportion among all the environments we test. Unpatched services and exposed devices, which we repeatedly encounter during internal penetration tests, were also among the same weaknesses behind the most serious infrastructure attacks of 2025.
According to the Mandiant M-Trends 2025 report, some of the most frequently exploited vulnerabilities affected network edge devices, VPN gateways, firewalls and routers. Three cases in particular defined 2025:
The other half of the story concerns identities, because this is where initial access most often turns into complete control over an organisation. According to the latest DBIR 2026, compromised credentials still play a role in approximately 39% of all data breaches.
Once an attacker gains access to the internal network, they encounter the same Active Directory weaknesses that we find in almost every internal penetration test:
Our internal analysis of all internal penetration tests confirms this trend. Spoofing of mDNS, NBNS and LLMNR protocols was identified in more than half of the networks we tested, making it one of the most common weaknesses overall.
New attack techniques are also emerging. The BadSuccessor vulnerability, introduced in 2025, abuses delegated Managed Service Accounts in Windows Server 2025 to obtain Domain Admin privileges. Microsoft did not release patches until August.
An internal environment can no longer be considered trusted by default. Whether initial access develops into a full-scale security incident now depends primarily on two factors: how quickly edge devices and services are updated, and how effectively identities are secured.
Do you know what would happen if an attacker gained access to your internal network?
Infrastructure penetration testing uncovers vulnerabilities, misconfigurations and attack paths that could lead to the compromise of your entire domain.
All news