Patching an internet-facing appliance fixes the vulnerability. It does not remove webshells, planted accounts, stolen session tokens or config changes an attacker made before you got there. After you apply the update, you need a deliberate compromise check: review authentication logs, compare the running configuration against a known good baseline, look for unexpected files and accounts on the appliance, and invalidate every active session and credential that passed through it.
This comes up now because the Canadian Centre for Cyber Security issued alert AL26-024 on September 27 for two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, then updated it again on October 3. When the same alert moves twice in a week, the situation on the ground is changing, not the paperwork.
What to look for after the patch
- Config diff. Export the running config and compare it to your last known good copy. Attackers add authentication policies, bind scripts and redirect rules that survive an update.
- Accounts and keys. List local admin accounts, API keys and SSH keys on the device. Anything you cannot trace to a person or a ticket gets removed.
- Files on disk. Appliance shells are restricted for a reason, but if the vendor gives you a way to list recently modified files in web-accessible directories, use it. Webshells are the common persistence method on gateways.
- Authentication logs. Look for logins from unusual geographies, successful authentications without a matching MFA event, and sessions that ran long after business hours.
- Outbound traffic. Check your firewall or flow logs for connections initiated by the appliance itself to addresses you do not recognize. A gateway should rarely be the one calling out.
- Session and credential reset. Kill all active sessions, rotate the device admin credentials, rotate any service account the appliance holds, and force reauthentication for users whose tokens could have been captured.
If you find something you cannot explain, stop touching the device and preserve what you have. A support bundle and a log export taken before you start cleaning are worth more than a tidy box.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Nobody owns the gateway
In assessments, the edge appliance is almost always the piece of the stack with no named owner. It was installed by someone who has since left, it sits outside the configuration management the application team uses, and its patch cadence depends on whoever happens to read the vendor bulletin. That is why it gets compromised. Put a person's name against every internet-facing device in your asset inventory, with a documented patch window and a defined source for vendor advisories. The security side of the house gets much easier once that list is real.
What auditors expect to see
Under SOC 2 and ISO 27001, the control is not "we patched it." It is evidence that you detected the advisory, assessed exposure, acted inside your own stated timeline and considered whether an incident occurred. Keep the advisory link, the date you were notified, the affected asset list, the patch confirmation and the compromise assessment notes together in one ticket. That single artifact answers a vulnerability management question, a change management question and an incident response question at once.
Set a standing rule: any critical vulnerability on an internet-facing device triggers both a patch and a compromise check, with the second step written down even when it finds nothing. The empty result is the evidence.
This started as a story in The Compliance Brief. Every Tuesday, Jacob picks the five security and compliance stories that change something for a company selling to enterprise buyers, and says what to do about each. This one was in issue 9.
Get the Brief every Tuesday