should have an IDS
A few years ago Ivanti introduced a internal file integrity checking feature in their system which runs every hour I think. It's not perfect but is a good start. They also have an offline version where you upload the code and the system reboots, runs the checks and reboots back to normal with results being logged to the log and output to the console.
Would be nice if Citrix and others had something similar. Netscaler is a more open platform with root shell access but such a tool could provide value regardless. Another udea for those running active/passive pairs is such a tool could be used to compare the two with the passive unlikely to be compromised as it's not listening to regular requests and could use it as a baseline.
Can't help but wonder short of an attacker causing damage how you may know your device is compromised or not(with reverse shels etc).
The build date on the patch is aug 20 I believe and obviously someone knew the exploit before the patch so maybe a few days before that was when Citrix started on developing the patch.
I haven't yet heard of attacks against netscaler that persist across reboots to survive a code upgrade but if they get root access it's pretty easy to do.