Three Unauthenticated Root RCEs Hit Cisco Nexus 3000 and 9000: Check Which Feature Is On
Cisco's NGOAM, MPLS OAM and NX-API flaws on Nexus 3000/9000 all score CVSS 9.8. Each needs a feature enabled; here's how to check.
· 6 minDesk · Vulnerability intelligence
Zero-days, proof-of-concept activity, exploit chains, and emergency patch windows.
Cisco's NGOAM, MPLS OAM and NX-API flaws on Nexus 3000/9000 all score CVSS 9.8. Each needs a feature enabled; here's how to check.
· 6 minSplunk patched CVE-2026-76268, a CVSS 9.8 unauthenticated RCE in the Patroni API on search head cluster members. Fixed in 10.4.3 and 10.2.7; no exploitation stated.
· 5 minAtlassian's CVSS 9.3 flaw lets anyone read files from eight Data Center products' web root without logging in. Fixed versions, mitigations and what to rotate.
· 7 minCVE-2026-88779, a SAML-only memory overflow in Citrix NetScaler, is on CISA KEV with a 7 October deadline. September's patch doesn't cover it.
· 5 minNext.js 16's next dev MCP endpoint skipped origin checks, letting a visited site read disk paths, source snippets, routes and logs. Low severity; fixed in 16.3.8.
· 5 minProject Zero's Forshaw details CVE-2026-66804, an incomplete fix for the Dark Elevator bug. A working exploit is public; August 2026 updates fix it.
· 5 minArista confirms active exploitation of CVE-2026-93952 in on-prem VeloCloud Orchestrator. CISA added it to KEV, but 6.1.x and 7.0.x have no listed fix.
· 4 minCISA added Adobe's critical Commerce and Magento authorization bug to KEV 44 days after the August patch. Stores on July builds should patch and triage.
· 5 min