Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

Cisco has issued a warning to customers regarding several critical vulnerabilities across its product lines, including three rated as critical. Two of these impact the Cisco IOS XR operating system, which powers the company's carrier-grade equipment, while the third affects certain Nexus 9000 Series Switches.
The company stated that many of these flaws were discovered during a "comprehensive internal security review," suggesting an extensive search for vulnerabilities. New versions of IOS XR have been released to address these issues, and Cisco strongly recommends that customers apply these updates.
One of the IOS XR vulnerabilities, identified as CVE-2026-20274, carries a CVSS score of 9.8. This flaw encompasses multiple buffering issues, the potential for out-of-bounds writes, and the initialization of resources with insecure default settings. Another critical IOS XR vulnerability, CVE-2026-20279, also rated 9.8, is described as an improper access control problem. This includes issues such as improper certificate validation, missing authentication for critical functions, and incorrect or missing authorization. In addition to these critical flaws, Cisco also identified a trio of vulnerabilities rated 8.8, another rated 8.6, and one scored 8.2.
The third critical vulnerability, CVE-2026-20212, was discovered by Cisco's support organization. This flaw affects certain Nexus 9000 Series Switches and stems from a problematic integration with Cisco's own Silicon One networking processors. It could allow an unauthenticated, remote attacker to execute code with root privileges on affected devices.
Specifically, TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF) configuration. An attacker could connect to an affected device and send specially crafted input, which would then be executed with root privileges. Exploitation of this vulnerability could also lead to the S1HAL process crashing, potentially causing the device to reload.
Ten Nexus 9000 devices are known to be affected by CVE-2026-20212. While a software update to permanently fix this flaw is not yet available, Cisco has provided guidance and a download to help implement mitigations. The company suggests using infrastructure access control lists (iACLs) to restrict traffic to only necessary management and control plane traffic destined for the affected device. Alternatively, iACLs can be configured to explicitly deny all TCP packets destined for a locally configured IP address on ports 43210 or 43211.
Cisco has confirmed that it has not observed any active attacks exploiting these vulnerabilities. However, the company advises prompt action given the public disclosure of these issues.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.