CISA adds Cisco ISE, Acronis flaws to KEV
CISA added two actively exploited vulnerabilities—Cisco ISE privileged API abuse and Acronis Backup default permissions flaw—to its KEV catalog, requiring federal remediation.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: CVE-2026-76460, an Incorrect Use of Privileged APIs vulnerability in Cisco Identity Services Engine (ISE), and CVE-2026-87886, an Incorrect Default Permissions vulnerability in Acronis Backup. Both entries indicate real-world exploitation is occurring, making these high-priority remediation targets for any organization running the affected products.
Under Binding Operational Directive (BOD) 26-04, FCEB agencies are required to prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that grant an attacker total control post-exploitation, and to determine whether systems were compromised prior to patching. While BOD 26-04 applies only to federal civilian agencies, CISA recommends all organizations adopt risk-based vulnerability management and treat KEV additions as priority patching items.
Defenders running Cisco ISE or Acronis Backup should identify affected versions immediately, apply vendor patches or mitigations, and review logs for signs of privileged API misuse (Cisco ISE) or exploitation of misconfigured default permissions (Acronis Backup) predating remediation. No further technical detail, IOCs, or exploitation specifics were provided in this bulletin.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free