← All briefings

Cisco Identity Services Engine · Acronis Backup for cPanel & WHM and Plesk · Google Pixel Cellular Modem

Date: 2026-09-17 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on 2026-09-16: Cisco Identity Services Engine, Acronis Backup integrations for cPanel/Plesk, and Google Pixel cellular-modem software. All have remediation deadlines of 2026-09-19. The Acronis entry materially increases the priority of exploitation reported yesterday. No additional new campaigns or European advisories were supplied.

Critical Vulnerabilities

CVE-2026-76460 — Cisco Identity Services Engine

  • Severity: Not supplied
  • EPSS: Not supplied
  • Technical detail: Cisco ISE and ISE Passive Identity Connector contain incorrect use of privileged APIs. An unauthenticated remote attacker may bypass the web-based management interface and gain unauthorized access to the affected device. Internet-exposed management interfaces are particularly high risk.
  • Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-16; known exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19.
  • Remediation: Apply Cisco’s security update immediately. Restrict ISE and ISE-PIC management access to trusted administration networks, review administrative and web-interface logs, and investigate unexpected configuration or account changes.

CVE-2026-87886 — Acronis Backup for cPanel & WHM and Plesk

  • Severity: Not supplied
  • EPSS: Not supplied
  • Technical detail: The Acronis Backup plugin and Plesk extension contain incorrect default permissions that may enable local privilege escalation. The affected integrations are commonly deployed on hosting and server-management platforms, where successful escalation could enable broader control of backup or hosted workloads.
  • Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-16; exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19. Exploitation was also reported in the previous briefing.
  • Remediation: Apply the vendor fix and verify file and directory permissions on cPanel, WHM and Plesk systems. Review for unexpected privileged processes, modified backup components, and unauthorized administrator activity.

CVE-2026-58704 — Google Pixel Cellular Modem

  • Severity: Not supplied
  • EPSS: Not supplied
  • Technical detail: Google Pixel cellular-modem software contains an improper authorization flaw caused by a logic error. An attacker may bypass permission checks and escalate privileges. The supplied data does not identify the required attack proximity or whether user interaction is necessary.
  • Exploitation status: NEW — Added to CISA KEV on 2026-09-16; known exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19.
  • Remediation: Deploy the applicable Pixel security update before the CISA deadline. Confirm update compliance for corporate mobile devices, prioritize high-risk users, and investigate unusual privilege changes or modem-related crashes where telemetry is available.

ONGOING

  • CVE-2026-76461 (Cisco Secure Email Gateway): actively exploited; patch before the 2026-09-17 CISA deadline and investigate for root-level compromise.
  • CVE-2026-85706 (GitLab CE/EE): actively exploited; patch and investigate arbitrary-file access.
  • CVE-2026-84869 (ConnectWise ScreenConnect): active exploitation reported; remediation is overdue.
  • CVE-2026-42016 / CVE-2026-42018 (JFrog Artifactory): actively exploited and reportedly chained; patch and rotate tokens.
  • CVE-2026-67277 / CVE-2026-86060 (MikroTik RouterOS): actively exploited; restrict management exposure.
  • CVE-2026-75650 (Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file changes.
  • CVE-2026-86218 (N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.
  • CVE-2026-81963 / CVE-2026-85880 (Windows): actively exploited; complete September updates.
  • CVE-2026-63520 (Microsoft SharePoint): exploitation and public PoC reported; verify patching and hunt for web shells.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut): exploitation reported; deploy current maintenance releases.

European Advisories

No new German or European advisory content was supplied for 2026-09-17. Previously reported BSI, EUVD and MISP items have no material update in the available data.

CVE-2026-76460 (Cisco ISE) and CVE-2026-87886 (Acronis Backup) should be correlated with relevant BSI and vendor advisories if present in local monitoring feeds; their CISA KEV status is covered in Critical Vulnerabilities.

Active Threats and Campaigns

  • CHOSEN BRICK spyware, BambooToken, KREMLIN banking malware and exposed Vite development-server credential theft remain ongoing from the previous briefing; no material new development was supplied.
  • GitLab, Artifactory, GrayRabbit and Microsoft 365 phishing activity remain under monitoring; continue hunting for web shells, unauthorized OAuth grants, suspicious authentication methods and endpoint persistence.

Security News and Context

  • CISA added CVE-2026-58704, CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities catalog on 2026-09-16, with remediation deadlines of 2026-09-19.
  • The Acronis Backup issue previously reported in connection with active exploitation is now formally listed in KEV, raising its remediation priority for affected hosting environments.
  1. Patch or isolate Cisco ISE and ISE-PIC immediately; review management-interface logs and configuration changes.
  2. Remediate Acronis Backup integrations on cPanel, WHM and Plesk systems before 2026-09-19; validate permissions and investigate privileged activity.
  3. Deploy Google Pixel security updates before the 2026-09-19 KEV deadline.
  4. Complete remediation of Cisco Secure Email Gateway before the 2026-09-17 deadline and investigate appliance integrity.
  5. Continue hunting for exploitation of actively targeted GitLab, ScreenConnect, Artifactory, SharePoint, Magento, Windows and PaperCut systems.
  6. Continue remediation of previously reported items: RouterOS, N-central, Oracle WebLogic, Delinea Secret Server, Chrome, MISP and exposed Vite development servers.