Emergency Advisories: How Fast Must You Patch a Perimeter Appliance

For an internet-facing VPN or firewall appliance with active exploitation, the answer is hours rather than days. When CISA issued Emergency Directive 24-01 in January 2024 over Ivanti Connect Secure, federal agencies were given deadlines measured in a couple of days, and attackers were already using the flaw. Your ordinary monthly patch process is not the process for this.
Why edge devices attract this treatment
Perimeter appliances sit in front of everything, terminate encrypted sessions, and hold credentials for the authentication systems behind them. They also tend to run software that customers cannot inspect, which means defenders find out about a problem when the vendor says so. Exploitation follows disclosure quickly because the target list is easy to build: internet-wide scanning identifies every exposed instance within hours. The result is a repeated pattern where a vulnerability is published on a Tuesday and mass exploitation is underway by Thursday.
Having an emergency route before you need it
You should agree an emergency change path in advance and rehearse it once. That means a named decision maker who can authorise an out-of-hours change, a defined process that skips the normal advisory board, and a communication plan so staff know remote access may drop. Keep the vendor’s advisory mailing list going to a monitored address rather than an individual, and maintain a list of your edge devices with versions and owners. Most delay in a real incident comes from working out who is allowed to say yes, not from the technical work.
“The pattern I see over and over is a client patching quickly and stopping there. If your appliance was exposed and vulnerable for two days, patching removes the vulnerability and does nothing about the access somebody may already have. Check the device for changes, rotate the credentials it held, and look at what those credentials touched before you call the incident closed.”
William Fieldhouse, Director, Aardwolf Security Ltd
When you cannot patch immediately
Reduce exposure while you wait. Restrict management interfaces to a small set of source addresses, disable the specific feature named in the advisory where the vendor provides that option, and consider taking the service offline if the business can tolerate it for a few hours. Vendor mitigations are usually configuration changes you can apply faster than a firmware upgrade, and applying both is normal. Record what you did and when, because that timeline becomes important if you later need to establish whether you were exposed during the window.
Assuming compromise afterwards
Treat a period of exposure as a possible breach and check accordingly. Compare the device configuration against a known good backup, look for new administrative accounts and unexpected scheduled tasks, run any integrity checker the vendor provides, and rotate every credential the appliance stored, including service accounts used for directory integration. Then look inward for signs of movement, since a stolen credential from an appliance is normally used somewhere else within a day or two. External penetration testing tells you what is currently exposed across the estate, and a vulnerability assessment service keeps the version inventory current so the next advisory takes minutes to triage rather than a day.
Frequently asked questions about emergency patching
These questions come up when an advisory lands on a Friday afternoon.
Should you wait for a stable release?
With active exploitation, no. Apply the vendor’s fix and accept the operational risk, because the alternative is remaining exploitable on a device attackers are already scanning for.
How do you know if you were compromised before patching?
Use the vendor’s indicators of compromise and your own logs. Absence of evidence is weak comfort on appliances with limited logging, which is why credential rotation is the sensible default after any exposure window.

