A patch existed. And a government ministry still took every Citrix environment it had offline for a weekend.
That's the part of last week's NetScaler story I can't stop thinking about.
In late September, Citrix patched two critical NetScaler ADC and Gateway bugs, CVE-2026-88771 and CVE-2026-88772. Both are remote code execution. Both scored CVSS 9.5. Both were already being exploited in the wild, per SDxCentral.
The fallout landed hardest in the Netherlands. The Ministry of the Interior took all of its Citrix environments offline over the weekend. Patients at two major hospitals couldn't see their own records. Frisius MC in Leeuwarden switched off some digital systems as a precaution.
Those are just the ones who said so out loud. This was a global bug.
If you run anything that sits between your people and their apps, this was your weekend too. Maybe not the gateway. But the next patch, the next zero-day, the next "upgrade by Monday or else."
And here's the uncomfortable thing. When the fix is sitting right there and you still choose to pull the plug, the problem isn't the patch. It's that you can't prove what the patch will do to everything downstream before you ship it.
So you pick between two bad options:
The Dutch ministry picked option two. Honestly, I'd probably have done the same. That's the problem.
We've spent a decade getting faster at finding holes and faster at shipping fixes. Detection is fast. Patching is fast.
The middle isn't. The bit where someone confirms that the fix doesn't break the workflow a nurse needs at 7 a.m. still takes days or weeks of people clicking through apps by hand. When attackers are already inside, you don't have weeks. So the middle gets skipped, or the whole service gets switched off.
The hole isn't the risk anymore. The fix is.
ATP360 won't patch your gateway. It's built for the middle. The endpoints and apps on the other side of it.
When a change lands — a Windows update, a new Citrix Workspace app build, an app update your vendor pushed overnight — ATP360 runs your real workflows against it, in your tenant, on real endpoints. Production is never touched. You get evidence: screenshots, logs, pass/fail by step. Then a human makes the call.
What that looked like in a recent run: a 13-stage build validated in 23 minutes. Work that used to take three weeks.
3 weeks → 23 minutes. Same build. Measured, not modeled.
That's the difference between "we turned it all off to be safe" and "we patched Saturday morning and we have the receipts."
Send us your scariest app. The one you'd least want to break on a weekend like that. We'll validate a real change against it, live, and you can watch.
P.S. ATP360 runs when you trigger it, per change. It isn't magic and it doesn't replace your patching tool or your detection. It sits between them so the person signing off has evidence instead of a gut feeling.