Edge and Identity Are Under Live Exploitation
A KEV clock, a PeopleSoft WAF bypass, an unpatched Authlib flaw, and an MCP token-theft bug all reward the same move: enforce below the byte the app acts on and below the credential the agent holds.
The common NetScaler mistake is treating the patch as the remediation. These zero-days were exploited globally for weeks before the Sep 27-28 advisory. Monday's public PoCs turned that into mass exploitation within hours. The patch closes the entry point but does not evict anyone already resident. Citrix's own detection script reads log history the appliance probably does not retain, so run the hunt against at least 30 days of SIEM data and search for the identified base64 strings after the User-Agent field. This box terminates TLS and brokers authentication, which means RCE on it puts every secret it holds in the presumptively-gone column. Rotate the TLS keys and the LDAP/RADIUS bind accounts, then kill active Gateway sessions.
Parser differentials are the recurring bug class
Ed Skoudis describes the PeopleSoft bypass correctly. The WAF matches /PSEMHUB/. Attackers send /%50SEMHUB/ (0x50 is 'P'), and the app decodes that to the same path. RFC 3986 treats percent-encoded unreserved characters as equivalent, so a rule that matches raw bytes is incomplete by specification. NetScaler's HTTP request smuggling bug (CVE-2026-88773, CVSS 9.3) has the same shape one layer down, at message boundaries. The invariant worth internalizing: the layer making the security decision must see the same bytes the application acts on. Every path-based WAF or ADC deny rule deserves a bypass suite in CI covering per-character and double percent-encoding, mixed-case hex, dot-segments, duplicate slashes, and overlong UTF-8.
The credential-forwarding twins
Two identity bugs share a root cause with the agent stories later in this briefing. Authlib has an unpatched empty-signature bypass (CERT/CC). The shape is the classic 'alg: none' case, where a missing signature is treated as vacuously valid. A validator in front of every token check should reject empty signature segments, enforce an algorithm allowlist, and pin issuer and audience. The second bug lives in the official MCP Python SDK, a confused-deputy flaw where a malicious MCP server can trick a client into handing over the OAuth credentials it uses for a real service. No CVE or fixed version was reported. The fix lines up exactly with the agent lesson. The agent process should hold no replayable credentials and have no direct network route. Instead, a broker injects short-lived, audience-bound tokens only on requests to allowlisted destinations, which leaves a rogue server nothing to steal.
The same principle applies to all outbound agent traffic. Egress should be default-deny and enforced below the agent (network namespace, forward proxy, firewall). The metadata endpoint at 169.254.169.254 should be blocked, and deny events should be wired to alerts.
What to do
Patch every NetScaler ADC/Gateway (including HA peers, DR, and lab boxes) before the Sep 30 KEV deadline, then run a webshell hunt against 30+ days of SIEM data and rotate TLS keys, bind credentials, and sessions on any box exposed pre-patch.
Put a validator in front of every Authlib token-verification call today (reject empty-signature tokens, enforce an algorithm allowlist, pin issuer and audience) and block production MCP clients from any server origin outside an explicit allowlist until pinned to a fixed SDK.
Build a canonicalization bypass regression suite for every path-based WAF and ADC deny rule and run it in CI on each edge config change.