Person using a VPN on a laptop, illustrating remote-access edge vulnerabilities exploited in VPN attack surface

What is Zero Trust Network Access

September 17, 2026 · 12 min read · By Nadia Kowalski

Key Takeaways:

  • Three separate VPN edge vulnerabilities were exploited in 2026: Check Point CVE-2026-50751 (CISA gave federal agencies three days to patch), Palo Alto GlobalProtect CVE-2026-0257, and a SonicWall SMA zero-day chain used by the Inc ransomware group.
  • ZTNA moves enforcement from the network layer to the application layer, so a compromised credential grants access to one app, not a flat network segment.
  • Pricing varies widely: Cloudflare Zero Trust is $7 per provisioned user per month on its Standard tier, while combined Zscaler SSE bundles are commonly quoted at roughly $150 to $250 per user per year.
  • A structured migration runs about 12 months for a 5,000-user enterprise, with a 2 to 4 week dual-access window before VPN rules are removed.
  • ZTNA is not a drop-in replacement for every protocol. Multi-threaded apps and server-initiated protocols like RDP and FTP still need bastions or protocol brokers.
  • SOC 2 auditors test eleven Common Criteria for remote access; modern ZTNA generates most of the required evidence as a byproduct of normal operation.

The 2026 VPN Attack Surface: Three Zero-Days in Three Months

Three separate remote-access edge vulnerabilities were exploited in the first half of 2026, each giving attackers a direct path from the public internet into a corporate network. The key issue is this: the appliance that terminates remote access is now the most valuable target on the perimeter, because compromising it produces valid sessions rather than noisy intrusion attempts.

Migration Guide: Six Phases from VPN to ZTNA

The most acute case was Check Point. CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities Catalog on June 8, 2026, and ordered Federal Civilian Executive Branch agencies to secure affected devices by June 11 under Binding Operational Directive 22-01, according to BleepingComputer’s reporting. The flaw allowed unauthenticated attackers to bypass authentication and establish a remote access VPN connection on Mobile Access, SSL VPN, and Spark firewall deployments configured with the deprecated IKEv1 key exchange. Check Point confirmed one incident tied to a Qilin ransomware affiliate and reported observed exploitation across a few dozen organizations globally.

Two other campaigns followed the same approach. Arctic Wolf Labs linked a series of June intrusions to a critical authentication bypass in Palo Alto Networks’ GlobalProtect portal and gateway, tracked as CVE-2026-0257, with exploitation beginning within days of disclosure, CSO Online reported. Qilin was the most active ransomware group in Q2 2026, responsible for 14% of attacks, according to NCC Group’s quarterly threat intelligence report cited in that coverage. The same article notes a credential-compromise campaign that exposed 75,000 FortiGate firewalls in June, and a CitrixBleed-like flaw in Citrix NetScaler devices that drew exploit attempts in the wild.

The common factor is architectural. A VPN concentrator authenticates a user once and then places that user on the corporate network. When the appliance is compromised, the attacker inherits that placement. Patching faster helps, but the access decision happens at the network boundary and is never revisited during the session.

Security Model: From Network Trust to Per-App Verification

ZTNA changes where the access decision is made and how often it is re-evaluated. A VPN grants network-level access after a single authentication event; the user then sees whatever the routing table and firewall rules permit. ZTNA grants access to a specific application, and the policy engine re-evaluates identity, device posture, and context for each session.

Security Model: From Network Trust to Per-App Verification
Security Model: From Network Trust to Per-App Verification, architecture diagram

Cisco’s cloud security team explained the difference clearly: “VPNs originally were sort of a castle-moat kind of concept in which if somebody provides the right credentials they get into our whole network, and that can be very dangerous,” said David Gormley, product marketing leader for Cisco Cloud Security, as reported by Network World. The replacement model grants “access to individual resource or app instead of whole network segment.”

The impact appears in blast radius. With a VPN, a stolen credential plus a successful connection means lateral movement potential across every reachable subnet. With ZTNA, the same credential reaches only the applications the user’s role is authorized for, and only from a device that passes posture checks. That is why ZTNA is often described as making the application, not the network, the unit of trust.

This model has a real cost. ZTNA requires an identity provider integration, a device posture signal source, and a policy engine that can express per-application rules. An organization with no centralized IdP and no endpoint management has to build that foundation before ZTNA delivers value. That dependency is the most common reason migration projects stall in discovery.

ZTNA Vendor Comparison: Architecture, PoPs, and Pricing

ZTNA is delivered through one of two product categories. Security Service Edge (SSE) bundles secure web gateway, cloud access security broker, and ZTNA as cloud-delivered services. Secure Access Service Edge (SASE) adds SD-WAN on top of SSE. Most enterprise evaluations in 2026 start by deciding whether they need SSE alone or full SASE, because that choice determines the shortlist.

The table below compares five platforms that appear on most enterprise shortlists, using figures from a July 2026 SASE platform comparison published by Decryption Digest and Cloudflare’s published pricing.

Platform Category Network footprint Notable architecture trait Pricing reference
Zscaler Zero Trust Exchange SSE (no native SD-WAN) 150-plus PoPs Proxy-based inline inspection; ZPA brokers app-level connections for private apps ZIA and ZPA licensed separately; combined SSE bundles commonly quoted at roughly $150 to $250 per user per year
Cloudflare One SSE with SD-WAN component 300-plus PoPs in over 100 countries Agentless access via Cloudflare Access for browser-based apps; WARP client for managed devices $7 per provisioned user per month on Standard tier; Enterprise contracts roughly $40 to $60 per seat per year at 500 to 2,000 seats
Netskope Intelligent SSE SSE (Borderless WAN for connectivity) 75-plus PoPs Inline and API-mode CASB with deep data-loss-prevention granularity See Netskope for current pricing
Cato Networks SASE Cloud Full SASE, converged from the ground up 80-plus PoPs SD-WAN and security share one traffic-processing pipeline and management plane See Cato Networks for current pricing

The trade-offs are structural. Zscaler’s proxy architecture allows deep inline inspection but makes every session dependent on Zscaler PoP availability, and the company does not offer SD-WAN natively, so full SASE transformations require a separate networking vendor. Cloudflare’s strength is point-of-presence density and developer-friendly API management, but its inline DLP and CASB API controls lag behind Netskope and Zscaler in policy granularity for mature data-protection use cases. Palo Alto’s advantage is policy continuity for organizations already standardized on PAN-OS firewalls, and the drawback is that the integration value only appears inside that ecosystem.

For infrastructure access specifically, a separate category of vendors brokers SSH, RDP, database, and Kubernetes sessions rather than general application access. A 2026 review of StrongDM described a bastionless model where agents run next to resources and the control plane issues short-lived credentials after SSO authentication, with session recording for audit. The review noted that the hosted control plane can add latency for globally distributed teams, and that costs scale with the number of resources and recorded sessions, which can surprise teams without retention carve-outs.

Performance and User Experience: Where the Latency Actually Goes

The performance argument for ZTNA is usually stated as “direct-to-app routing beats backhaul.” The routing method matters more than the slogan. A traditional VPN routes remote user traffic through a centralized concentrator, so a user in Singapore accessing a SaaS application hosted in Frankfurt may traverse the corporate data center in Virginia first. ZTNA platforms route the session through a PoP near the user, which shortens the path.

The gain is not free. Every ZTNA session passes through a policy enforcement point, and the added hop introduces its own latency. The migration playbook published by Zero Trust Insider in August 2026 sets a practical target of about 30 milliseconds of added latency for web applications, and recommends aiming for parity or better on interactive protocols such as RDP by placing connectors close to the application rather than forcing traffic through a distant cloud gateway. That is the operational version of the PoP-density argument: a vendor with 300 PoPs will generally beat one with 75 for a globally distributed workforce, because the enforcement point sits closer to the user.

User experience depends heavily on the access model chosen. Agent-based ZTNA supports the widest protocol range, including RDP, SSH, and custom TCP, and provides continuous posture signals, but requires an endpoint agent. Agentless ZTNA works through the browser with no installation, which suits contractors and third parties, but is weaker for non-HTTP protocols. Most enterprises use a hybrid model: agentless for general SaaS access, agents for privileged users and legacy protocols.

Migration Guide: Six Phases from VPN to ZTNA

The most common migration failure is replicating VPN access patterns in ZTNA policy. A team that maps every VPN ACL to an equivalent ZTNA rule rebuilds the broad-access problem with new tooling. The migration playbook from Zero Trust Insider names this directly among its pitfalls, along with treating identity verification as sufficient without device compliance checks.

The sequence that practitioners follow, drawn from that playbook and Versa Networks’ VPN-to-ZTNA migration guide, runs in six phases:

  • Discovery and baseline (2 to 6 weeks). Build a definitive application inventory with protocol, owner, user population, peak concurrency, and criticality. Use network flow telemetry plus interviews with application owners, because scheduled jobs and integration accounts are the most commonly missed dependencies.
  • Architecture selection. Choose agent, agentless, or hybrid access, and decide whether enforcement lives in cloud gateways, on-premises connectors, or in-app sidecars. Use your existing identity provider for primary authentication and add hardware attestation and short-lived machine certificates for service-to-service connections.
  • Pilot (4 to 8 weeks). Start with one non-critical internal web application and 20 to 200 users. Run in monitor mode for two to four weeks to collect real traffic and exceptions before enforcing blocks.
  • Phased rollout (8 to 16 weeks). Expand to medium-risk applications and broader user groups. Add bastions or protocol brokers for legacy protocols. Remove VPN ACLs for migrated applications as coverage stabilizes.
  • Dual-access window and cutover. Keep VPN and ZTNA access running concurrently for a bounded window, commonly two to four weeks, with automated rollback playbooks. Then decommission VPN rules and update runbooks and the configuration management database.
  • Validation and continuous tuning. Test authentication flows including mid-session posture changes, and measure authentication latency and end-to-end application latency against the VPN baseline.

For a 5,000-user enterprise, the playbook’s example timeline runs about 12 months: weeks 0 to 6 for discovery, weeks 7 to 14 for the pilot, weeks 15 to 32 for expansion to 1,500 to 2,000 users, and weeks 33 and beyond for high-risk and legacy workloads. Legacy complexity, not tooling maturity, extends the tail.

Compliance Mapping: SOC 2, ISO 27001, and GDPR Evidence

ZTNA changes the evidence an auditor collects, and in most cases it makes collection easier. The AICPA Trust Services Criteria touch eleven criteria relevant to remote access, concentrated in CC6 (Logical and Physical Access Controls) and CC7 (System Operations), according to an analysis of SOC 2 remote-access controls.

Control What the auditor asks Evidence a ZTNA deployment produces
CC6.1 logical access security How is user identity verified, and how is the authentication mechanism protected? SSO integration with the corporate IdP, MFA challenge logs per user, device posture requirements, per-session authentication logs with timestamp, user, device, and source IP
CC6.3 access removal Show that terminated employees lost access within the policy window SCIM-driven deprovisioning when the IdP disables the user, access revocation logs with timestamps, session kill events on active tunnels
CC6.6 perimeter security What prevents unauthorized access from the internet to internal systems? No internal services exposed publicly, per-policy segmentation so tunnels land only in permitted resources, device posture enforced at tunnel establishment
CC6.7 transmission security How is data protected in transit? TLS 1.3 or WireGuard encryption on every tunnel, cipher suite configuration aligned to current guidance

Two findings recur. The first is shared accounts: auditors object to any account without a unique identity, so if a service account retains direct ZTNA access while corporate infrastructure still uses shared credentials, it gets flagged. The second is posture signals checked at session establishment but never re-evaluated, which leaves a gap if a device is compromised mid-session.

For GDPR, the relevant obligation is Article 32, which requires appropriate technical measures to ensure a level of security appropriate to the risk. The playbook flags one ZTNA-specific privacy issue to handle early: device posture telemetry is personal data. Collect only the attributes you actually enforce on, and document retention and lawful basis for that collection.

Common Pitfalls and What They Cost

Three failure modes cause most troubled migrations. Skipping deep discovery leads to cutover incidents, because forgotten services behind broad VPN rules cause breakage when those rules are removed. Over-trusting posture signals without behavioral context leaves the identity-and-session attack surface open. Rushing cutover without automated rollback turns a policy error into an outage.

A fourth pitfall is protocol coverage. Cisco’s Gormley noted that multi-threaded applications and those relying on server-initiated communication protocols such as RDP or FTP do not fit well with the ZTNA model, which can force organizations to run both VPN and ZTNA during the transition. That dual-stack period adds cost and user confusion, and it should be planned as a bounded window rather than an indefinite state.

The cost case depends on what is being replaced. Cloudflare’s Standard tier at $7 per provisioned user per month undercuts most VPN licensing for small and mid-sized teams, and the Free tier supports up to 50 users with 24-hour log retention, which is adequate for evaluation but insufficient for incident response or audit. At enterprise scale, combined Zscaler SSE bundles commonly quoted at roughly $150 to $250 per user per year are not cheaper than a VPN license on a line-item basis. The savings come from retiring concentrator hardware, eliminating the patch cycle on internet-facing appliances, and reducing the blast radius of credential theft.

The last point explains the case clearly. ZTNA does not stop credential theft. It limits what a stolen credential allows an attacker to do, from a network foothold to a single application session, and it removes the internet-facing appliance that three ransomware campaigns exploited in 2026. For organizations preparing for a SOC 2 Type II period or an ISO 27001 surveillance audit, the evidence trail that ZTNA generates as a byproduct of normal operation is a second, less-discussed benefit. For more on how access controls fit alongside encryption and key management obligations, see our analysis of enterprise compliance standards for data security.

More in-depth coverage from this blog on closely related topics:

Sources and References

Sources cited while researching and writing this article:

Nadia Kowalski

Has read every privacy policy you've ever skipped. Fluent in GDPR, CCPA, SOC 2, and several other acronyms that make people's eyes glaze over. Processes regulatory updates faster than most organizations can schedule a meeting about them. Her idea of light reading is a 200-page compliance framework, and she remembers all of it.