Daily Security Intel

Archives
Log in
Subscribe
September 4, 2026

[SecurityIntel] 04 Sep | Critical Cisco Nexus Root RCE Flaw Actively Threatens

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, September 04, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Cisco Nexus Root RCE Flaw Actively Threatens

CRITICAL

5

C2 IPs

4

OTX IOCs

32

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by critical remote code execution vulnerabilities in Cisco Nexus 9000 switches and HPE ArubaOS-CX network operating systems. Additionally, active exploitation of WordPress plugins (Elementor Pro and a migration plugin) and the deployment of Pegasus zero-click spyware against Serbian activists emphasize the diverse nature of current threats. Organizations must also defend against novel phishing tactics, such as ASCII smuggling, and supply chain compromises targeting developer infrastructure like Coder.

■ CRITICAL STORIES

CRITICAL#1

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on Silicon One-based Cisco Nexus 9000 switches, posing an immediate threat to enterprise network infrastructure.

CRITICAL#2

Critical Elementor Pro flaw exploited to take over WordPress sites

Attackers are actively exploiting CVE-2026-32475 in the widely used Elementor Pro plugin to upload webshells and execute arbitrary commands, leading to complete site compromise.

HIGH#3

Coder's registry infrastructure compromised to push malicious modules

Attackers compromised Coder's Cloudflare-managed infrastructure to inject unauthorized registry servers, delivering malicious Terraform modules designed to steal developer credentials.

HIGH#4

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

Citizen Lab confirmed a zero-click iMessage exploit was used to deploy NSO Group's Pegasus spyware against Serbian political opposition and activists, highlighting highly targeted state-sponsored surveillance.

■ CVEs IDENTIFIED

CVE-2026-32475

Elementor Pro (WordPress Plugin) — Remote Code Execution / Webshell Upload

Critical

CVE-2026-19949

WordPress Migration Plugin — SQL Injection / Remote Code Execution

High

[CVE-TBD-1]

Cisco Nexus 9000 Series Switches (Silicon One-based) — Unauthenticated Remote Code Execution as Root

Critical

[CVE-TBD-2]

HPE ArubaOS-CX — Remote Code Execution

Critical

■ THREAT ACTORS

NSO Group

Commercial Spyware Vendor

Deploying Pegasus spyware via zero-click iMessage exploits against Serbian activists

Shai-Hulud Actor

Cybercriminal / Worm Operator

Utilizing an updated infostealer worm targeting 469 credential locations across developer environments

BraZetsu Operator

Cybercriminal

Distributing Python-based Windows malware to compromise hosts for illicit marketplace inventory

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Active exploitation of CVE-2026-32475 in Elementor Pro and CVE-2026-19949 in WordPress migration plugin
T1195.001
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Compromise of Coder's Cloudflare infrastructure to distribute malicious Terraform modules
T1566.002
Phishing: Spearphishing Link | StreamRat banking Trojan distributed via malicious Meta and TikTok ads; ASCII smuggling used to bypass email filters
T1203
Exploitation for Client Execution | Pegasus zero-click spyware exploit targeting iMessage on iOS
T1539
Steal Web Session Information | Infostealers capturing authenticated sessions to bypass MFA
T1552
Unsecured Credentials | Shai-Hulud infostealer searching 469 locations for developer and cloud credentials

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Cisco — Nexus 9000 Switches — Unauthenticated remote code execution as root — [THN]

[P1 PATCH NOW]≤24h

HPE — ArubaOS-CX — Critical remote code execution vulnerability — [BC]

[P1 PATCH NOW]≤24h

Elementor — Elementor Pro WordPress Plugin (CVE-2026-32475) — Actively exploited RCE and webshell upload — [BC]

[P1 PATCH NOW]≤24h

WordPress — Migration Plugin (CVE-2026-19949) — High-severity SQL injection leading to remote code execution — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the critical RCE vulnerability in Cisco Nexus 9000 Series switches immediately to prevent unauthenticated root-level code execution.
2[P1] Update the Elementor Pro plugin for WordPress to the latest version to remediate CVE-2026-32475 and prevent active webshell exploitation.
3[P1] Apply security updates for HPE ArubaOS-CX network operating systems to mitigate the critical remote code execution flaw.
4[P1] Update the affected WordPress Migration Plugin to patch CVE-2026-19949 and block SQL injection and RCE vectors.
5[P2] Audit all Terraform deployments and verify Coder registry configurations to ensure no unauthorized or malicious modules were pulled during the Cloudflare infrastructure compromise.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 05 Sep | Critical RCEs Actively Exploited Older → [SecurityIntel] 03 Sep | BGP Hijack Delivers Malicious Virtualizor Software Updates
Powered by Buttondown, the easiest way to start and grow your newsletter.