Germany's intelligence reform gives the BND and the domestic service new powers to act, up to switching off the servers of state hacker groups. What it does not contain is any rule on when a vulnerability known to the state must be reported so the vendor can fix it. The clause that would have routed the BSI's vulnerability findings to the BND was deleted before cabinet after critics fought it. Nothing replaced it. For anyone who runs firewalls and VPN gateways in Germany, that gap matters more than the clause ever did.
I work on firewall estates in German enterprises as an independent contractor. The appliances I configure are the same class of device that state attackers use as a front door. After this reform, Germany's own services will have a legal mandate to attack infrastructure and no written process telling them when to tell a vendor what they know. I am less interested in the civil-liberties debate here than in a practical question: what should the edge of a German network now assume?
What did the Bundestag actually debate on 24 September?
On 24 September 2026 the Bundestag held the first reading of the government's bill to modernise German intelligence law, Drucksache 21/7868, and referred it to the Interior Committee. The Bundestag's own summary names active measures, such as shutting down the servers of state hacker groups, as part of the package. Telepolis lists more, citing the government's own examples: deleting victims' data held by hacker groups, manipulating deliveries with faulty components, and getting into the IT of drone factories or chemical-weapons labs to sabotage production. Interior Minister Alexander Dobrindt said in the debate that the services should move from observing threats to actively preventing them.
The money follows the mandate. The BND's budget is planned to rise from €1.51 billion in 2026 to around €1.85 billion in 2027, an increase of about €342 million. A service with offensive cyber powers and a growing budget will build and buy offensive capability. Offensive capability against modern networks means unpatched vulnerabilities.
Which clause was deleted, and why was that not a fix?
The draft published on 5 July 2026 contained a planned § 10(2) of the BND Act that would have obliged the BSI, Germany's federal cyber-security agency, to pass the vulnerabilities it learns about to the BND, zero-days included, ideally in an automated feed. Dennis-Kenji Kipker argued in heise that this would turn the agency whose job is to close holes into a supplier for the service that wants them open. The working group AG KRITIS warned that the rule would weaken IT security rather than strengthen it, and that critical-infrastructure operators would have to ask how far they could still trust the BSI. The Green MP Konstantin von Notz called the clause negligent and incompatible with the Federal Constitutional Court's requirements. Before the cabinet decision on 12 August 2026 the obligation was taken out, as ARD journalist Florian Flade reported on X on 10 August (summarised here).
| Draft of 5 July 2026 | Bill as debated on 24 September 2026 | |
|---|---|---|
| BSI duty to pass vulnerabilities to the BND | Yes, planned § 10(2) BND Act | Deleted before cabinet on 12 August |
| Active cyber measures, such as switching off attacker servers | Yes | Yes |
| Written process deciding when a known hole is disclosed or kept | No | No |
The deletion removed a bad rule and left no rule at all. Blogspan put the remaining gap in one sentence: Germany still has no legally regulated balancing process that decides when a vulnerability known to the state gets reported and when it is held back. A written rule can be read, criticised in a committee hearing and challenged in Karlsruhe. An unwritten practice leaves the hold-or-report decision with whoever happens to own the case, and nobody outside the service ever learns how it was made.
Does Germany have a rule for when its services must report a zero-day?
No. As of the first reading, no German statute sets out when the BND or the domestic intelligence service (BfV) has to disclose a vulnerability it holds to the vendor or to the BSI. What exists is a statement of intent. On 26 August 2026 BfV president Sinan Selen said at a Bitkom press conference in Berlin, as heise reported, that systematically exploiting vulnerabilities and keeping them from the BSI was “not the operative approach”. He added an image any firewall engineer will recognise: you cannot pretend to have secured the front door while deliberately leaving the terrace door open at the back.
I take him at his word, and it is still not a control. An auditor would not accept “our admins say they don't do that” as evidence for a privileged-access policy, and I see no reason to accept it from a service that now has a statutory mandate for offensive operations. The United States, not a country known for restraint in this area, has published the charter of its Vulnerabilities Equities Process since November 2017. You can argue about how well that process works. You can at least read it.
Why does this land on firewalls and VPN gateways?
Firewalls and VPN gateways sit where offensive operators want to be, and the exploitation numbers show it. Google's Threat Intelligence Group counted 90 zero-days exploited in the wild in 2025. Forty-three of them, 48%, hit enterprise technology, an all-time high, and 21 of those were in security and networking products. Google adds that just over half of the zero-day exploitation it could attribute to state espionage groups targeted edge devices and security appliances, because those boxes are hard to monitor and give long-term footholds.
Put that next to the German reform. A service allowed to switch off foreign attacker servers needs a way in, and the way in to most networks is the appliance at the edge. Edge appliances are a global product line: the gateway model a foreign target runs is the model sitting in a German hospital or Stadtwerk. A hole held for an operation abroad stays open in German racks for as long as it is held. That is the terrace door Selen described, and today nothing in law decides how long it stays open.
What changes in how I design the edge
I don't think the answer is to patch faster. Patching is necessary and I have argued for controls that prove they work for years, but patch speed only helps against holes the vendor knows about. A vulnerability held by a state service, German or foreign, is by definition one the vendor has not fixed. The design question changes from “how fast do we close the window?” to “what can an attacker do from inside the firewall itself once the window was never closed?”
| Patch-speed posture | Assume-compromised-edge posture | |
|---|---|---|
| Threat it covers | Known holes, after the vendor ships a fix | Holes nobody has disclosed yet |
| Management plane | Reachable from wherever admins happen to be | Only from a separate management network and jump hosts |
| Credentials on the appliance | Directory accounts with broad rights | Local or narrowly scoped accounts, treated as burned on compromise |
| Logs | Kept on the box | Shipped off the box to a store the appliance cannot rewrite |
| Behind the firewall | A flat inside network | Segments the gateway cannot reach on its own |
Three of those rows are where I spend most of my review time. The management plane comes first: if the admin interface of a gateway answers on any interface an attacker can touch, a single exploit hands over the configuration and every secret stored in it. The second is identity. A VPN gateway that binds to the directory with an account that can read half of it gives an intruder the map of the organisation on day one, a point I made in the case for continuous verification. The third is what sits behind the box. An edge appliance with a direct path to everything inside turns one held zero-day into a full breach, which is the same structural mistake I described in the firewall flaw and the AI-agent breach and in two authentication bypasses with one root cause. Segmentation behind the gateway is the part of a zero-trust plan for the Mittelstand that pays off here.
The engineering here is old; the reason to insist on it is recent. Until now I could tell a German client that the main threat to their edge came from criminal groups and foreign services, and that their own state at least wanted the holes closed. After this reform the honest version is that their own state will also hold offensive capability against the same product lines, with no published rule for when it gives a hole back. A design that already assumes the edge is compromised does not need to know who is holding the exploit.
What the Interior Committee should add
The bill is now in committee, and this is the stage where a missing paragraph can still be written. The fix does not have to be the old BSI clause in reverse. It needs a process with a few properties: a body outside the services that decides on retention, a default towards disclosure, time limits with forced review, and a published annual count of vulnerabilities held and released. Operators who answer to NIS2 already have to document how they handle vulnerabilities. Asking the same of a state that now has a mandate to use them is not a high bar. My view from the rack: write the rule down first, then argue about it in public.