U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploit 2026-9-17 09:26:14 Author: securityaffairs.com(查看原文) 阅读量:3 收藏

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini September 17, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-76460 (CVSS score of 10.0) Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
  • CVE-2026-87886 (CVSS score NA) Acronis Backup Incorrect Default Permissions Vulnerability
  • CVE-2026-58704 (CVSS score of 8.8) Google Pixel Improper Authorization Vulnerability

CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw is caused by inadequate authentication checks on a specific API endpoint. An unauthenticated remote attacker could exploit it by sending a specially crafted request, potentially gaining unauthorized access to the affected system through its web-based management interface.

“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” reads the advisory.

CVE-2026-87886 is a local privilege escalation vulnerability in Acronis Backup caused by insecure file permissions. The flaw affects the Acronis Backup plugin for cPanel & WHM and the Backup extension for Plesk. A local attacker with limited privileges could exploit the issue to manipulate files used by the backup service and potentially execute code with elevated, root-level privileges. Acronis reported exploitation in the wild in limited in limited, targeted attacks

Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has already been exploited in the wild.

The third vulnerability added to the KeV catalog is an Improper Authorization flaw tracked as CVE-2026-58704.

Google has addressed the flaw with the release of its September 2026 Pixel security update.

“In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the advisory.

The vulnerability is an elevation-of-privilege issue caused by a permission bypass resulting from a logic error in the modem code. Google said there are indications that the flaw may have been used in “limited, targeted exploitation.”

Unlike vulnerabilities affecting applications or higher-level Android components, CVE-2026-58704 resides in the cellular modem, a security-sensitive component responsible for communications between the device and mobile networks. The company warned that it has already been exploited in the wild.

“There are indications that CVE-2026-58704 may be under limited, targeted exploitation.” states Google.

As usual, the IT giant has not disclosed who exploited the vulnerability, how many devices were targeted, or what the attacks were designed to achieve.

The vulnerability is particularly notable because it does not require user interaction. According to the CVE record, exploitation can result in remote, proximal or adjacent privilege escalation without requiring additional execution privileges.

The technical details suggest that an attacker able to reach the vulnerable modem environment could exploit the permission bypass to obtain higher privileges. The attack vector is classified as adjacent rather than broadly Internet-facing, an important distinction when assessing the practical exploitation requirements.

In this case, however, Google has not publicly described the complete attack chain. There is also no evidence in the company’s advisory identifying the operation as the work of a commercial spyware vendor or a specific state-sponsored group.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the GitLab and ConnectWise flaws by September 14, 2026, while the remaining JFrog Artifactory issues must be addressed by September 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/199239/security/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh