60
60
60
CISA Adds Two Known Exploited Vulnerabilities to Catalognew
CISA added actively exploited CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its KEV catalog.
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-76460, an incorrect use of privileged APIs flaw in Cisco Identity Services Engine, and CVE-2026-87886, an incorrect default permissions flaw in Acronis Backup. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV vulnerabilities on publicly exposed assets that grant total control post-exploitation, and check whether systems were compromised before patching.
68
50
60
60
60
60
60
60
60
60
60
60
60
60
60
60
45
60
60
60
60
57
60
60
45
60
60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
60
60
60
60
60
60
60
60
60
60