Your Router and Firewall Need Patches Too. This Week Proved It.

Oct 9, 2026Incognito CyberSecurity

Your Router and Firewall Need Patches Too. This Week Proved It.

🇲🇽 Leer en Español →

Quick question: when did someone last update the box that connects your office to the internet? If you can’t answer, you’re in good company. This week’s headlines say that’s a problem worth fixing.

Infographic: 3 steps to protect your office network - know what you own, turn on updates, retire old gear

What happened this week

Cisco released fixes for a dozen critical vulnerabilities. SonicWall, whose firewalls sit in plenty of small offices, patched flaws that could let attackers get past login protections or run their own code. Citrix pushed an urgent patch for its NetScaler remote-access gear. And several US states are now going after TP-Link over router security flaws.

Different brands, same lesson: the gear at the edge of your network is a computer running software, and software has bugs.

Why this matters more than a laptop update

Think of your router and firewall as the lock on your front door. You wouldn’t keep using a lock you knew could be picked in seconds. Yet that’s what an unpatched firewall is.

It faces the whole internet

Attackers don’t pick targets by hand. Automated tools scan the internet around the clock looking for devices with known flaws. A small office isn’t too small to be found.

Nobody feels responsible for it

Someone installed it years ago. It works, so nobody touches it. That’s exactly how a device ends up three years behind on updates.

One weak box exposes everything behind it

Your files, your point-of-sale system, your cameras and your staff’s laptops all sit behind that device. If it falls, the attacker starts inside your building.

Three places small offices get caught

The set-it-and-forget-it firewall

Installed once, never updated. It keeps humming along, quietly out of date.

The router your internet provider handed you

It’s easy to assume the provider keeps it current. Often nobody does. If it came free with your plan, find out who is responsible for updating it.

Gear the vendor has retired

When a manufacturer stops supporting a model, new flaws never get fixed. No setting makes that safe. The only fix is replacement.

What you can do this week

  1. Make a list. Write down every router, firewall, VPN box and Wi-Fi access point, with brand and model.
  2. Check the firmware. Log in, or ask your IT provider, whether each device is on the current version.
  3. Turn on automatic updates. If the device can’t do that, set a monthly calendar reminder.
  4. Lock the admin door. Change default admin passwords and turn off remote administration from the internet unless you truly need it.
  5. Check the support status. If the vendor no longer patches your model, put a replacement in this quarter’s budget.
  6. Test your backups. If something does get through, a tested backup is what keeps you in business.

This is the kind of work our small business cyber security solutions take off your plate. Our endpoint protection covers the computers behind your firewall, our secure data backups are your safety net, and spam and virus filtering stops a lot of trouble before it arrives. Your team matters too: see our cybersecurity awareness training. If you missed it, read Your Software Vendor Got Hacked. Is Your Data in the Pile? for the vendor side of the same story, or browse all our posts.

The bottom line

Patching isn’t glamorous, but it is cheap compared to a breach. The router and firewall are the easiest devices to forget and the first ones attackers test. Put them on a schedule and this week’s headlines become someone else’s problem.

Not sure when your firewall was last updated?

We’ll look at your network and tell you plainly where you stand. No pressure, no jargon.

Book a complimentary visit

Send us a message

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

— Nemuel Cruz, Incognito Cyber Security

Sources: SecurityWeek, Cisco Patches a Dozen Critical Vulnerabilities; SonicWall and Splunk Patch Critical Vulnerabilities; TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws (October 8, 2026).

About the author

Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News