Postmortem

CitrixBleed and MOVEit: what a stack watchtower would have shown

Updated 2026-08-28

CitrixBleed and MOVEit were not subtle. They were KEV-class events on products companies forgot they still ran. A SaaS watchtower does not replace patching — it names the blast radius on the day CISA does.

The pattern is not “zero-day.” It is “we still have that box.”

CitrixBleed (CVE-2023-4966) leaked session tokens from NetScaler. MOVEit Transfer (CVE-2023-34362 and follow-ons) became a ransomware supply-chain story. Both spent time as news, then as KEV, then as board questions: were we on it, who owns it, when did we know?

Scanners help if the device is in inventory. Many Citrix and file-transfer boxes were not. SaaS-first companies still had them in a closet, at a subsidiary, or at a payroll vendor. The failure was awareness across the vendor list, not a missing CVSS decimal.

What the briefing should have contained

CVE identifier. Product name as CISA wrote it. Whether it matched a tool you listed (direct) or a parent/supplier. Ransomware-use flag if present. Required action in CISA’s words. A link to the advisory. That is a page, not a 30-page threat report.

ZeroDayTracker stores exactly that shape. Citrix and Ivanti are in the catalog because hybrid estates are real. MOVEit-class file-transfer tools should be named on your stack if you still run them — we cannot match a vendor you did not add.

Do not wait for the meme

By the time a vulnerability has a nickname, defenders who needed the first 48 hours have already lost them. KEV plus a named catalog is how a company without a CTI desk gets the first 48 hours at all. Newsletters are slower. Twitter is louder. Neither is a watchlist.

All guides · SaaS KEV tracker

Watch the SaaS that holds your data.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing