ZeroHour
Product

Acronis Backup

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

Security Affairsupdated · 1h agofirst · 3h agoExploit / PoC in the wild 21 sourcesCVE-2026-76460CVE-2026-87886CVE-2026-587041

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added actively exploited CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its KEV catalog.

CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-76460, an incorrect use of privileged APIs flaw in Cisco Identity Services Engine, and CVE-2026-87886, an incorrect default permissions flaw in Acronis Backup. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV vulnerabilities on publicly exposed assets that grant total control post-exploitation, and check whether systems were compromised before patching.

CISA Advisories · 1d agoExploit / PoC in the wildCVE-2026-76460CVE-2026-87886

Related CVEs

  • Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC
    Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.
    · Cisco Identity Services Engine (ISE) · Cisco ISE Passive Identity Connector (ISE-PIC) KEV PoC large
  • Incorrect Default Permissions in Acronis Backup Plugin for cPanel & WHM and Plesk Enable Privilege Escalation
    CVE-2026-87886 is an incorrect default permissions flaw (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Because files or objects installed by the plugin/extension carry overly permissive default permissions, a local attacker with low-privileged access to a Linux hosting server can abuse them to escalate privileges. Successful exploitation grants elevated Linux privileges on the hosting server, which could enable persistence, access to hosted customer data, or further lateral movement. Any hosting provider or administrator running the Acronis Backup integration on cPanel & WHM or Plesk servers is affected. The flaw was added to the CISA KEV catalog on 2026-09-16, and multiple reports describe targeted attacks exploiting it in the wild, though no public proof-of-concept is known and ransomware use is undetermined.
    · Acronis Backup plugin for cPanel & WHM · Acronis Backup extension for Plesk KEVmoderate
  • Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation
    A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments.
    · Google Cellular Modem (modem firmware on Google Pixel-class devices, per assigning CNA) KEVmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.