BLOG | Jul 20, 2026

Protecting Vulnerable and Poorly Configured Network Devices

From advisory to verified state: how Forward closes the gap
Manish Kalra
Manish Kalra
Senior Director
Product Marketing
 
Who should read this post?
  • Network and security teams responsible for hardening routers, switches, and firewalls against state-sponsored targeting
  • Organizations in the sectors named in CSA AA26-194A: defense industrial base, communications, energy, financial services, government facilities, and healthcare
  • Network engineers and architects who need to verify configuration compliance across large, multi-vendor networks
What is covered in this content?
  • What CSA AA26-194A requires of network defenders, and the assumption built into every measure
  • Why an accurate, up-to-date device inventory is the prerequisite for the advisory
  • How Forward Enterprise finds legacy SNMP, weak credentials, exposed Smart Install, and unpatched devices across the full network

On July 13, 2026, NSA, CISA, the FBI, and co-sealing partners from twelve other countries published AA26-194A, a joint Cybersecurity Advisory (CSA) warning that Center 16 of Russia's Federal Security Service (FSB) continues to exploit vulnerable and poorly configured network devices across the defense industrial base, communications, energy, financial services, government facilities, and healthcare sectors. The advisory does not reference new exploits. It focuses on poorly configured networking devices, primarily routers, that can be exploited. 

The mitigation list comes down to six key actions network defenders must take. Implementing it across a production network, one built from years of vendor turnover, staff changes, undocumented changes, acquisitions, and regional IT decisions, is more difficult than it sounds. 

What are the AA26-194A hardening measures 

AA26-194A builds on the FBI's August 2025 public service announcement on Russian targeting of networking devices, and it lands on six hardening measures every network device owner is urged to adopt: 

  • Disable Cisco Smart Install where it is not in active use 
  • Implement SNMPv3 in place of legacy SNMPv1 and SNMPv2 
  • Use strong, unique passwords on every device  
  • Monitor and restrict access to SNMP OIDs 
  • Restrict management protocols 
  • Update software and firmware to patch known vulnerabilities 

Implementing each one of these requirements assumes network teams have an accurate, up-to-date inventory of all assets. 

Six measures, one problem 

Turning guidance like this into action requires current, verified network behavior, not the state of the network as documented in a diagram or a spreadsheet from the last audit, but the state of every device as it is configured today. That is where the Forward Enterprise mathematically accurate network digital twin comes in. It builds a vendor-agnostic digital twin of the hybrid network by collecting configuration and state data from every router, switch, and firewall, then makes that data queryable in plain language through Forward AI. 

Implementing CSA AA26-194A with Forward Enterprise 

  1. Confirm Cisco Smart Install is off everywhere
    What used to require a change ticket per device to verify becomes a single query in Forward Enterprise. A network defender can find every device where Cisco Smart Install is present and has not been explicitly disabled.
  1. Find every device running legacy SNMP
    Instead of pulling configs from thousands of devices manually, a network defender can ask Forward AI which devices have SNMPv3 disabled or are still accepting SNMPv1 or v2 and get a complete list across the entire hybrid network in minutes.
  1. Find weak and shared passwords
    Forward Enterprise's config search runs pattern matching for default credential remnants, cleartext passwords, and shared enable secrets across every device in the network at once, replacing the device-by-device review that would make implementing this measure time-consuming.
  1. Monitor and restrict access to SNMP OIDs
    Forward Enterprise's config search identifies which SNMP MIBs and/or OIDs are configured on each device, so a defender can see read and write access at the OID level instead of assuming the SNMP service is all or nothing. In addition, Forward enterprise includes queries for Security Technical Implementation Guides for DoD Security compliance including applicable SNMP configuration compliance.
  1. Prove protocols are blocked
    A firewall rule that blocks a protocol on paper, and a network that enforces that block end to end are two different things. Forward Enterprise's path analysis models traffic hop by hop across ACLs, security policies, and routing together to confirm the following protocols are blocked:
    • User Datagram Protocol (UDP) port 69
    • (TFTP)Transmission Control Protocol (TCP) port 4786 (SMI)
    • UDP ports 161 and 162 (SNMP)TCP/UDP ports 10161 and 10162 (SNMPv3)
    • TCP/UDP ports 10161 and 10162 (SNMPv3)

    Before that rule ships, Forward Predict can run the same change against the network digital twin to catch cases where a blocked protocol is quietly carrying legitimate management traffic that would break on deployment.
  1. Know which devices to patch first
    Forward Enterprise maintains an accurate inventory tied to every device, cross-referenced against known vulnerabilities and exposure. Instead of a general upgrade mandate, network and security teams get a prioritized list: which devices are exposed, which vulnerabilities are known-exploited, and which upgrade closes the largest gap first.

Accurate inventory is the missing step, not the fix list 

Every one of these fixes starts with the same unstated requirement: an accurate, up-to-date inventory of every device on the network. You cannot implement SNMPv3 on devices you do not know exist. You cannot disable Cisco Smart Install on a router that fell off last year's spreadsheet. You cannot patch what you cannot see. Most network teams don't have that inventory; they have the last one someone had time to build, already stale by the time the next advisory lands. 

Each of these measures in AA26-194A is a known, well-understood fix. The hard part is proving, across a network of any real size, that it's been applied everywhere and stays applied as the network changes. Security advisories describe the threat. Forward Enterprise describes the network as it is, so that the response to the next advisory is a query, not a project. 

For step-by-step instructions, check out our community post by Chris Naish. 

See how you can meet the requirements of Cybersecurity Advisory AA26-194A. Book a  1:1 demo with a Forward product expert.

Industry Recognition

Winner of over 20 industry awards, Forward Enterprise is the best-in-class network modeling software that customers trust

Customers are unanimous:
Forward Enterprise is a game-changer

From Fortune 50 institutions to top level federal agencies, users agree that Forward Enterprise is unlike any other network modeling software

Most Recent

Browse all posts

Subscribe to our newsletter

Make sure you don't miss a post by signing up here for our monthly 'Moving Forward' newsletter

Ready to get started?

Top cross