ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 19 sources: “Cisco September 2026 ISE Hardening Release Patches Actively Exploited Zero-Day Authentication Bypass CVE-2026-76460 (CVSS 10.0)” — merged summary and timeline →

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 80CVE-2026-76460CVE-2026-87886CVE-2026-58704
AI summary · glm-5.3-flash

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

  • CVE-2026-76460 (CVSS 10.0): unauthenticated API authentication bypass in Cisco ISE, confirmed actively exploited
  • CVE-2026-87886: insecure file permissions in Acronis Backup plugins allow local root-level code execution
  • CVE-2026-58704: Pixel modem permission bypass enables adjacent privilege escalation with no user interaction
  • All three flaws have confirmed in-the-wild exploitation, though scope and attribution remain undisclosed
  • Federal agencies must patch per BOD 22-01 deadlines; private organizations are urged to review the catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-58704
Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation

A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments.

Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios.

8.8 KEV
  • Google Cellular Modem (modem firmware on Google Pixel-class devices, per assigning CNA)
masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide)
CVE-2026-76460
Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC

Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.

Do: Upgrade ISE and ISE-PIC to the fixed releases specified in Cisco's security advisory (fixed versions are not provided in the available data); because the flaw is on CISA's KEV list, federal agencies must patch or apply mitigations per BOD 26-04 timelines. Until patched, restrict access to the web-based management interface to trusted administrative networks only, verify no unintended exposure via firewalls/ACLs, and monitor for unauthenticated access attempts against the interface.

10.0 KEV
  • Cisco Identity Services Engine (ISE)
  • Cisco ISE Passive Identity Connector (ISE-PIC)
large≈10,000–100,000 ISE/ISE-PIC appliance deployments worldwide, of which an estimated low thousands have internet-reachable management interfaces
CVE-2026-87886
Incorrect Default Permissions in Acronis Backup Plugin for cPanel & WHM and Plesk Enable Privilege Escalation

CVE-2026-87886 is an incorrect default permissions flaw (CWE-276) in the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Because files or objects installed by the plugin/extension carry overly permissive default permissions, a local attacker with low-privileged access to a Linux hosting server can abuse them to escalate privileges. Successful exploitation grants elevated Linux privileges on the hosting server, which could enable persistence, access to hosted customer data, or further lateral movement. Any hosting provider or administrator running the Acronis Backup integration on cPanel & WHM or Plesk servers is affected. The flaw was added to the CISA KEV catalog on 2026-09-16, and multiple reports describe targeted attacks exploiting it in the wild, though no public proof-of-concept is known and ransomware use is undetermined.

Do: Upgrade the Acronis Backup plugin for cPanel & WHM and the Plesk extension to the latest versions specified in Acronis's security advisory, since fixed version numbers are not provided in the available data. Audit affected Linux hosting servers for signs of local privilege escalation (unexpected setuid/permission changes, new privileged accounts, unusual cron or service activity), and restrict low-privileged shell access to the server where possible. As the flaw is on CISA's KEV list, federal and BOD 26-04-bound stakeholders must apply vendor mitigations on internet-exposed and high-risk assets on an accelerated timeline.

KEV
  • Acronis Backup plugin for cPanel & WHM
  • Acronis Backup extension for Plesk
moderatelikely thousands to tens of thousands of cPanel/WHM and Plesk hosting servers with the Acronis Backup integration installed
Full article681 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 17, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-76460 (CVSS score of 10.0) Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
  • CVE-2026-87886 (CVSS score NA) Acronis Backup Incorrect Default Permissions Vulnerability
  • CVE-2026-58704 (CVSS score of 8.8) Google Pixel Improper Authorization Vulnerability

CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw is caused by inadequate authentication checks on a specific API endpoint. An unauthenticated remote attacker could exploit it by sending a specially crafted request, potentially gaining unauthorized access to the affected system through its web-based management interface.

“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” reads the advisory.

CVE-2026-87886 is a local privilege escalation vulnerability in Acronis Backup caused by insecure file permissions. The flaw affects the Acronis Backup plugin for cPanel & WHM and the Backup extension for Plesk. A local attacker with limited privileges could exploit the issue to manipulate files used by the backup service and potentially execute code with elevated, root-level privileges. Acronis reported exploitation in the wild in limited in limited, targeted attacks

Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has already been exploited in the wild.

The third vulnerability added to the KeV catalog is an Improper Authorization flaw tracked as CVE-2026-58704.

Google has addressed the flaw with the release of its September 2026 Pixel security update.

“In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the advisory.

The vulnerability is an elevation-of-privilege issue caused by a permission bypass resulting from a logic error in the modem code. Google said there are indications that the flaw may have been used in “limited, targeted exploitation.”

Unlike vulnerabilities affecting applications or higher-level Android components, CVE-2026-58704 resides in the cellular modem, a security-sensitive component responsible for communications between the device and mobile networks. The company warned that it has already been exploited in the wild.

“There are indications that CVE-2026-58704 may be under limited, targeted exploitation.” states Google.

As usual, the IT giant has not disclosed who exploited the vulnerability, how many devices were targeted, or what the attacks were designed to achieve.

The vulnerability is particularly notable because it does not require user interaction. According to the CVE record, exploitation can result in remote, proximal or adjacent privilege escalation without requiring additional execution privileges.

The technical details suggest that an attacker able to reach the vulnerable modem environment could exploit the permission bypass to obtain higher privileges. The attack vector is classified as adjacent rather than broadly Internet-facing, an important distinction when assessing the practical exploitation requirements.

In this case, however, Google has not publicly described the complete attack chain. There is also no evidence in the company’s advisory identifying the operation as the work of a commercial spyware vendor or a specific state-sponsored group.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the GitLab and ConnectWise flaws by September 14, 2026, while the remaining JFrog Artifactory issues must be addressed by September 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199239/security/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html