Today’s Field Note

Three edge-facing bugs are in play and two are already being hit. CERT Polska reports active exploitation of a critical Zimbra Collaboration Suite RCE, the same product that has been a persistent target for years. GitLab’s CVE-2026-19478, an unauthenticated flaw that lets attackers modify or delete public projects and user data, went from disclosure to exploitation almost immediately. Meanwhile Citrix NetScaler has a critical unauthenticated auth bypass (no user interaction required) that is patched but not yet widely exploited, which historically means you have days, not weeks. All three sit at the perimeter, all three are the kind of thing that turns into a foothold before you finish reading the advisory.

Today’s Action

  • Patch Zimbra Collaboration Suite now and hunt for webshells and anomalous mailbox access predating the fix; assume compromise if you were exposed.
  • Apply the GitLab fix for CVE-2026-19478 immediately, then audit public projects and user data for unauthorized modification or deletion.
  • Patch Citrix NetScaler for the auth bypass before PoCs mature, and review session and config integrity for signs of pre-patch access.
  • Pull all three appliances’ logs and check for exploitation attempts and unexpected outbound connections since disclosure.
  • Confirm these systems are not needlessly internet-facing; restrict management interfaces to VPN or allowlisted ranges.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

The edge does not wait for your change window.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.