Cisco Identity Services Engine · Acronis Backup for cPanel & WHM and Plesk · Google Pixel Cellular Modem
Date: 2026-09-17 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on 2026-09-16: Cisco Identity Services Engine, Acronis Backup integrations for cPanel/Plesk, and Google Pixel cellular-modem software. All have remediation deadlines of 2026-09-19. The Acronis entry materially increases the priority of exploitation reported yesterday. No additional new campaigns or European advisories were supplied.
Critical Vulnerabilities
CVE-2026-76460 — Cisco Identity Services Engine
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: Cisco ISE and ISE Passive Identity Connector contain incorrect use of privileged APIs. An unauthenticated remote attacker may bypass the web-based management interface and gain unauthorized access to the affected device. Internet-exposed management interfaces are particularly high risk.
- Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-16; known exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19.
- Remediation: Apply Cisco’s security update immediately. Restrict ISE and ISE-PIC management access to trusted administration networks, review administrative and web-interface logs, and investigate unexpected configuration or account changes.
CVE-2026-87886 — Acronis Backup for cPanel & WHM and Plesk
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: The Acronis Backup plugin and Plesk extension contain incorrect default permissions that may enable local privilege escalation. The affected integrations are commonly deployed on hosting and server-management platforms, where successful escalation could enable broader control of backup or hosted workloads.
- Exploitation status: STATUS CHANGE — Added to CISA KEV on 2026-09-16; exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19. Exploitation was also reported in the previous briefing.
- Remediation: Apply the vendor fix and verify file and directory permissions on cPanel, WHM and Plesk systems. Review for unexpected privileged processes, modified backup components, and unauthorized administrator activity.
CVE-2026-58704 — Google Pixel Cellular Modem
- Severity: Not supplied
- EPSS: Not supplied
- Technical detail: Google Pixel cellular-modem software contains an improper authorization flaw caused by a logic error. An attacker may bypass permission checks and escalate privileges. The supplied data does not identify the required attack proximity or whether user interaction is necessary.
- Exploitation status: NEW — Added to CISA KEV on 2026-09-16; known exploitation is confirmed by catalog inclusion. CISA remediation deadline: 2026-09-19.
- Remediation: Deploy the applicable Pixel security update before the CISA deadline. Confirm update compliance for corporate mobile devices, prioritize high-risk users, and investigate unusual privilege changes or modem-related crashes where telemetry is available.
ONGOING
CVE-2026-76461(Cisco Secure Email Gateway): actively exploited; patch before the 2026-09-17 CISA deadline and investigate for root-level compromise.CVE-2026-85706(GitLab CE/EE): actively exploited; patch and investigate arbitrary-file access.CVE-2026-84869(ConnectWise ScreenConnect): active exploitation reported; remediation is overdue.CVE-2026-42016/CVE-2026-42018(JFrog Artifactory): actively exploited and reportedly chained; patch and rotate tokens.CVE-2026-67277/CVE-2026-86060(MikroTik RouterOS): actively exploited; restrict management exposure.CVE-2026-75650(Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file changes.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-81963/CVE-2026-85880(Windows): actively exploited; complete September updates.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC reported; verify patching and hunt for web shells.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation reported; deploy current maintenance releases.
European Advisories
No new German or European advisory content was supplied for 2026-09-17. Previously reported BSI, EUVD and MISP items have no material update in the available data.
CVE-2026-76460 (Cisco ISE) and CVE-2026-87886 (Acronis Backup) should be correlated with relevant BSI and vendor advisories if present in local monitoring feeds; their CISA KEV status is covered in Critical Vulnerabilities.
Active Threats and Campaigns
- CHOSEN BRICK spyware, BambooToken, KREMLIN banking malware and exposed Vite development-server credential theft remain ongoing from the previous briefing; no material new development was supplied.
- GitLab, Artifactory, GrayRabbit and Microsoft 365 phishing activity remain under monitoring; continue hunting for web shells, unauthorized OAuth grants, suspicious authentication methods and endpoint persistence.
Security News and Context
- CISA added CVE-2026-58704, CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities catalog on 2026-09-16, with remediation deadlines of 2026-09-19.
- The Acronis Backup issue previously reported in connection with active exploitation is now formally listed in KEV, raising its remediation priority for affected hosting environments.
Recommended Actions
- Patch or isolate Cisco ISE and ISE-PIC immediately; review management-interface logs and configuration changes.
- Remediate Acronis Backup integrations on cPanel, WHM and Plesk systems before 2026-09-19; validate permissions and investigate privileged activity.
- Deploy Google Pixel security updates before the 2026-09-19 KEV deadline.
- Complete remediation of Cisco Secure Email Gateway before the 2026-09-17 deadline and investigate appliance integrity.
- Continue hunting for exploitation of actively targeted GitLab, ScreenConnect, Artifactory, SharePoint, Magento, Windows and PaperCut systems.
- Continue remediation of previously reported items: RouterOS, N-central, Oracle WebLogic, Delinea Secret Server, Chrome, MISP and exposed Vite development servers.