CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added actively exploited CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its KEV catalog.
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-76460, an incorrect use of privileged APIs flaw in Cisco Identity Services Engine, and CVE-2026-87886, an incorrect default permissions flaw in Acronis Backup. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV vulnerabilities on publicly exposed assets that grant total control post-exploitation, and check whether systems were compromised before patching.
- CVE-2026-76460: Cisco ISE incorrect use of privileged APIs, actively exploited.
- CVE-2026-87886: Acronis Backup incorrect default permissions, actively exploited.
- BOD 26-04 mandates rapid federal patching of KEV vulnerabilities on exposed assets.
- Agencies must determine whether systems were compromised before the patch was applied.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76460 | Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending. Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface. | 10.0 | — | KEV |
| large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces | |
| CVE-2026-87886 | Incorrect Default Permissions in Acronis Backup Plugin for cPanel & WHM and Plesk Enable Privilege Escalation CVE-2026-87886 is an incorrect default permissions flaw (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Because files or objects installed by the plugin/extension carry overly permissive default permissions, a local attacker with low-privileged access to a Linux hosting server can abuse them to escalate privileges. Successful exploitation grants elevated Linux privileges on the hosting server, which could enable persistence, access to hosted customer data, or further lateral movement. Any hosting provider or administrator running the Acronis Backup integration on cPanel & WHM or Plesk servers is affected. The flaw was added to the CISA KEV catalog on 2026-09-16, and multiple reports describe targeted attacks exploiting it in the wild, though no public proof-of-concept is known and ransomware use is undetermined. Do: Upgrade the Acronis Backup plugin for cPanel & WHM and the Plesk extension to the latest versions specified in Acronis's security advisory, since fixed version numbers are not provided in the available data. Audit affected Linux hosting servers for signs of local privilege escalation (unexpected setuid/permission changes, new privileged accounts, unusual cron or service activity), and restrict low-privileged shell access to the server where possible. As the flaw is on CISA's KEV list, federal and BOD 26-04-bound stakeholders must apply vendor mitigations on internet-exposed and high-risk assets on an accelerated timeline. | — | — | KEV |
| moderatelikely thousands to tens of thousands of cPanel/WHM and Plesk hosting servers with the Acronis Backup integration installed |
Full article233 words · extracted from cisa.gov · click to collapse
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog