securityaffairs.com 17 Sept 2026, 09:26 UTC

CISA Warns of Active Exploitation in Cisco, Acronis and Pixel Flaws

CISA Warns of Active Exploitation in Cisco, Acronis and Pixel Flaws

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue: CVE-2026-76460 in Cisco Identity Services Engine (ISE), CVE-2026-87886 in Acronis Backup, and CVE-2026-58704 in Google Pixel devices. Cisco’s flaw has a CVSS score of 10.0 and is an authentication bypass caused by inadequate checks on an API endpoint.

An unauthenticated remote attacker could send a specially crafted request to gain unauthorised access through the web-based management interface. Cisco’s PSIRT said it was aware of active exploitation and urged customers to upgrade to a fixed release.

CVE-2026-87886 is a local privilege-escalation flaw caused by insecure file permissions in the Acronis Backup plugin for cPanel & WHM and the Backup extension for Plesk. A limited-privilege local attacker could manipulate backup-service files and potentially execute code with root-level privileges. Acronis reported exploitation in limited, targeted attacks.

CVE-2026-58704 affects the cellular modem in Google Pixel devices and has a CVSS score of 8.8 in CISA’s listing, although the article cites a CVSS score of 8.0 elsewhere. It is an improper-authorisation flaw involving a permission bypass caused by a logic error, potentially enabling remote, proximal or adjacent privilege escalation without user interaction. Google’s September 2026 Pixel security update addresses it and says there are indications of limited, targeted exploitation.

Federal agencies must remediate KEV entries under Binding Operational Directive 22-01, while other organisations are advised to review the catalogue and apply the relevant updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline