Patching a vulnerability is not the end of the incident. Citrix Bleed (CVE-2023-4966) allowed attackers to steal valid session tokens from Citrix ADC appliances. Many organisations patched promptly — but did not terminate active sessions, leaving the already-stolen tokens valid and usable. The advisory from CISA and FBI explicitly warned about this, but many organisations missed the step. After any patch for an authentication, session management, or access control vulnerability, invalidate all active sessions and require re-authentication. This applies to web applications, VPNs, and cloud consoles.
Tags