Search
Find merged stories by title or summary.
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-76460 (CVSS score of 10.0) Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability • CVE-2026-87886 (CVSS score NA) Acronis Backup Incorrect Default Permissions Vulnerability • CVE-2026-58704 (CVSS score of 8.8) Google Pixel Improper Authorization Vulnerability CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw is caused by inadequate authentication checks on a specific API endpoint.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability • CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7. 8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux
[CISA] CVE-2026-87886 - Confirmed Exploitation
CVE-2026-87886 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-16 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-16 Asserted: 2026-09-16
You've reached the end of current stories for this search.
