All news

16 September 2026 / 3 minutes of reading

Infrastructure penetration testing: why the internal network has become the epicentre of critical risks

71% of the infrastructure projects we tested contained at least one critical vulnerability. Most of these vulnerabilities were hidden in systems that companies considered secure simply because they were “not publicly accessible.


Infrastructure projects were our second most common type of engagement in 2025. We tested 104 of them, accounting for approximately 17% of all projects. This was also where we encountered the highest number of severe findings across all areas: 74 critical and 125 high-severity vulnerabilities, representing an average of almost two critical or high-severity vulnerabilities per project.

At the same time, as many as 71% of infrastructure projects contained at least one critical vulnerability—the highest proportion among all the environments we test. Unpatched services and exposed devices, which we repeatedly encounter during internal penetration tests, were also among the same weaknesses behind the most serious infrastructure attacks of 2025.

According to the Mandiant M-Trends 2025 report, some of the most frequently exploited vulnerabilities affected network edge devices, VPN gateways, firewalls and routers. Three cases in particular defined 2025:

  • Ivanti Connect Secure (CVE-2025-0282): a vulnerability enabling unauthenticated remote code execution. A China-linked threat group was actively exploiting it before a security patch became available, making it a zero-day vulnerability.
  • Citrix NetScaler (CVE-2025-5777): known as CitrixBleed 2, this vulnerability allowed attackers to steal session tokens and bypass multi-factor authentication (MFA). Only a few weeks after its disclosure, it was added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) Catalog.
  • Cisco ASA and Cisco FTD: these products were targeted in a large-scale zero-day campaign exploiting CVE-2025-20333 and CVE-2025-20362, which affected VPN web servers. The vulnerabilities were considered so severe that, after adding them to the KEV Catalog, CISA issued an emergency directive.

The other half of the story concerns identities, because this is where initial access most often turns into complete control over an organisation. According to the latest DBIR 2026, compromised credentials still play a role in approximately 39% of all data breaches.

Once an attacker gains access to the internal network, they encounter the same Active Directory weaknesses that we find in almost every internal penetration test:

  • a lack of segmentation between standard workstations and domain controllers,
  • service accounts whose passwords can be obtained offline using Kerberoasting,
  • missing SMB and LDAP signing, enabling attacks such as NTLM Relay,
  • misconfigured Active Directory Certificate Services (AD CS) templates, also known as ESC vulnerabilities, which allow a standard user to escalate their privileges to those of a domain administrator.

Our internal analysis of all internal penetration tests confirms this trend. Spoofing of mDNS, NBNS and LLMNR protocols was identified in more than half of the networks we tested, making it one of the most common weaknesses overall.

New attack techniques are also emerging. The BadSuccessor vulnerability, introduced in 2025, abuses delegated Managed Service Accounts in Windows Server 2025 to obtain Domain Admin privileges. Microsoft did not release patches until August.

What does this mean for CISOs?

An internal environment can no longer be considered trusted by default. Whether initial access develops into a full-scale security incident now depends primarily on two factors: how quickly edge devices and services are updated, and how effectively identities are secured.

 

Do you know what would happen if an attacker gained access to your internal network?

Infrastructure penetration testing uncovers vulnerabilities, misconfigurations and attack paths that could lead to the compromise of your entire domain.

logo

Sign up for our newsletter for all the important cybersecurity and ethical hacking news.

© 2024 citadelo AG. All rights reserved.

facebooklinkedinxyoutube