CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours

India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

ThreatVectr Newsdesk· 3 min read
CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours
Share

CERT-In wants critical vulnerabilities on internet-exposed systems patched inside 12 hours of disclosure where feasible, and the rationale is blunt: attackers are using LLMs to shorten the gap between a public CVE and a working exploit.

The guidance, published this week by the Indian Computer Emergency Response Team, applies to any organisation operating internet-facing infrastructure under Indian jurisdiction. That covers a lot. Government bodies, banks regulated by the RBI, listed companies, payment processors, and the long tail of SaaS vendors hosting Indian customer data all fall inside the perimeter.

If your team is used to a 30-day patch SLA, the new number will sting. The 12-hour clock starts at advisory publication, not at the moment your scanner picks it up the next morning. For edge devices (Citrix NetScaler, Fortinet FortiGate, Ivanti Connect Secure, Cisco ASA, the usual suspects), that window is the whole point. These are the boxes that keep showing up in CISA's Known Exploited Vulnerabilities catalogue within days of disclosure.

CERT-In points to AI-assisted vulnerability research as the accelerant. And the data backs that up. Mass exploitation of CVE-2023-4966 (Citrix Bleed) hit within a week of the patch. CVE-2024-3400 on Palo Alto GlobalProtect was being exploited before the fix shipped. The trend line is not subtle.

A few honest caveats. "Where feasible" is doing real work in that sentence. Patching a clustered NetScaler pair or a production Exchange edge inside 12 hours without a maintenance window is not how most shops operate, and CERT-In knows it. The expectation is that you either patch, apply a vendor-documented mitigation, or take the asset offline. Doing nothing for a week is what the guidance is trying to kill.

For smaller teams without a 24x7 SOC, this is mostly a forcing function to fix things you already knew were broken: no asset inventory of external attack surface, no out-of-hours change process, no pre-approved emergency patch path. Fix those once and the 12-hour number becomes survivable.

The enforcement question is open. CERT-In's 2022 incident-reporting directions had teeth via the IT Act; whether these patching timelines get the same treatment will determine how seriously boards take them.

What to do this week:

  1. Build (or refresh) an external attack surface inventory. You cannot patch what you do not know is exposed.
  2. Subscribe to vendor PSIRT feeds for every edge device you own, and route them to a pager, not a shared inbox.
  3. Pre-approve an emergency change window with your CAB for CVSS 9.0+ on internet-facing assets.
  4. Document a mitigation-first playbook (WAF rule, ACL, service disable) for when a vendor patch is not yet available.
  5. Run one tabletop this quarter where the scenario is a Friday-evening edge CVE with public PoC.

Twelve hours is short. Most of the work happens before the clock starts.

© 2026 Threat Vectr