Today’s Field Note

Two edge-facing bugs are already being turned. Attackers are exploiting Citrix NetScaler auth bypass CVE-2026-19490 in the wild per Previdian, and if the last few years taught you anything, NetScaler compromises end in webshells, session theft, and quiet persistence that survives the patch. Separately, Arctic Wolf is tracking exploitation of the PaperCut chain (CVE-2026-81578 auth bypass plus CVE-2026-82078 RCE) against schools and universities across the US and Europe, used for command execution, recon, and credential harvesting. NetScaler and PaperCut are both the kind of forgotten appliances that sit internet-exposed and unpatched for months. That is the whole game here: neither is exotic, both are exposed, and both are being hit today.

Today’s Action

  • Patch Citrix NetScaler for CVE-2026-19490 now, then hunt for post-exploit activity (rogue sessions, new files in NSIP web dirs, unexpected admin logins) because patching does not evict an existing intruder.
  • Apply the PaperCut fixes for CVE-2026-81578 and CVE-2026-82078; if you run PaperCut in education, treat it as already probed.
  • Pull PaperCut off the public internet or put it behind SSO/VPN, and rotate any credentials it stored or brokered.
  • Review NetScaler and PaperCut logs back to the disclosure window for command execution and recon, not just from today.
  • Confirm neither appliance is exposed via forgotten NAT rules or shadow deployments before you call it done.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

It’s not if your NetScaler is exposed, it’s who found it first.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.