
We found a Nexus instance on a client's external network running default creds, noticed CVE-2026-3199 had just dropped, and decided to dig in rather than move on. The NVD entry was wrong, no writeup existed, and the patch diff was 52k lines. Used an LLM to triage it and had confirmed RCE in under two hours. Full kill chain + defensive guidance here: https://www.armadin.com/blog-posts/writeup-to-weaponization-cve-2026-3199-llm-assisted-rce-exploitation
Post summary
Discovered a Nexus instance with default credentials, confirmed CVE‑2026‑3199 allows RCE in under two hours, and provided a blog post detailing the kill chain and defensive guidance.




