The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Three Cisco Nexus 9000 Flaws Allow Remote Root Access as KEV Grows

The Perimeter Desk
2026-09-04
# Three Cisco Nexus 9000 Flaws Allow Remote Root Access as KEV Grows The Monday morning ritual for most security teams is a slow drift through a sea of CVEs, looking for a reason to tell the production lead that they need to take systems offline. The production lead's incentive is simple: zero downtime. The security team's incentive is slightly more complex: don't be the person who ignored the warning in the post-mortem. Today, Friday 4 September 2026, that tension just hit a breaking point. If you aren't looking at your Cisco Nexus 9000 switches right now, you're gambling with root access. Three new flaws—CVE-2026-20212, CVE-2026-20274, and CVE-2026-20279—have hit the board today. They aren't just "critical" in a theoretical sense; they allow unauthenticated remote attackers to run code as root. In plain English: if you're running these switches exposed, you've essentially handed the keys to your data center backbone to whoever is scanning the internet this afternoon. Then we have the CISA Known Exploited Vulnerabilities (KEV) list, which is the only list that actually matters because it proves the attackers have already done the hard work for us. The priority ranking for this week isn't a debate; it's an triage operation. First, the "House is on Fire" tier. This includes JFrog Artifactory (CVE-2026-82329) and Sangoma Switchvox (CVE-2026-9586). Both are currently seeing high activity in the wild and carry the highest severity rankings. The Artifactory flaw is particularly nasty because of the second-order effect. If an attacker compromises your binary repository, they aren't just stealing data; they're poisoning the well. Every single developer and deployment server that pulls a package from a compromised JFrog instance is now distributing malware to your customers. Your breach becomes your clients' breach. Second, the "Get it Done by Tomorrow" tier. CISA has set a federal patch deadline of 2026-09-05 for several entries added this Wednesday. That includes SonicWall SMA1000 appliances (CVE-2026-83548 and 83549) and Kestra OSS (CVE-2026-49869). If you're in the federal space, you have roughly 24 hours. If you aren't, you should still be sweating. SonicWall appliances are favorite beachheads for state-sponsored groups because they sit right on the edge of the network. Third, the "Necessary but Not Immediate" tier. PaperCut NG/MF (CVE-2026-82078 and 81578) has a deadline of 2026-09-14. It's being exploited, yes, but it rarely provides the same immediate systemic collapse as a root-level switch flaw or a poisoned repository. Patch it, but don't let it distract you from the Cisco Nexus situation. Now, let's talk about what can wait. You can likely push BerriAI LiteLLM (CVE-2026-59822) and Kludex Starlette (CVE-2026-48710) to next week, provided your implementation isn't directly exposed to the open web without any other guards. The deadlines for these are 2026-09-16. In a world of limited manpower, spending four hours on an internal AI proxy while your core switches are screaming "Root Access Allowed" is a failure of leadership. Companies love to release statements saying they "take security seriously," but their patching cadences tell the real story. The gap between a vulnerability being added to the KEV and a company actually deploying the fix is where most breaches live. We saw this pattern during the Ivanti spree last year—the patch existed, but the fear of breaking a legacy workflow outweighed the risk of a breach until the data was already on a leak site. The objection here is always "stability." The admin will tell you that patching a core switch or a repository server mid-quarter risks a catastrophic outage. They'll argue that the controlled environment reduces the risk. That argument is a lie. The risk isn't reduced; it's just invisible until it's total. An outage caused by a patch is a scheduled event with a rollback plan. An outage caused by a ransomware group that entered through an unpatched SonicWall appliance is a corporate tragedy. Which brings us to the question that usually makes the CISO uncomfortable: If your current patching priority is based on CVSS scores provided by vendors rather than active exploitation data from CISA, who are you actually protecting—the company's assets or your own performance review? Check the Nexus switches first. The rest can wait until Monday, except for the ones that have to be done by tomorrow.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day The Hacker News
  2. (LEAD) Nearly 40 mln Tving accounts compromised in massive data breach: probe - Yonhap News Agency Google News Security
  3. Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal SecurityWeek
  4. Data breach at South Korean streaming service Tving affects 39 million accounts - MLex Google News Security
  5. Tving Data Breach Exposes 39.54 Million Accounts, Double Initial Estimate - thelec.net Google News Security
  6. Critical Elementor Pro flaw exploited to take over WordPress sites BleepingComputer
  7. Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News
  8. 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm - TechRadar Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.