The addition of CVE-2026-76460 and CVE-2026-87886 to CISA's Known Exploited Vulnerabilities catalog highlights an increasingly important cybersecurity challenge: attackers are targeting the infrastructure organisations depend upon to enforce access controls and recover from security incidents. The two vulnerabilities affect different products and involve separate exploitation techniques, but they expose a common architectural concern because both reside in software that typically operates with elevated privileges or trusted relationships inside enterprise environments. CVE-2026-76460 affects Cisco Identity Services Engine and Cisco ISE Passive Identity Connector, potentially allowing an unauthenticated remote attacker to bypass authentication and gain unauthorized access to an affected device, while CVE-2026-87886 affects Acronis Backup integrations for cPanel, WHM and Plesk and can allow an attacker who already possesses low-privileged access to escalate those privileges. Both vendors have acknowledged exploitation in the wild, making these vulnerabilities immediate operational concerns rather than merely theoretical weaknesses discovered during routine security testing. 

The Cisco ISE vulnerability is particularly significant because Identity Services Engine frequently acts as a central authority for network access control, authentication, authorization and device visibility. Organisations deploy ISE to help determine which users and devices should be permitted to connect to corporate infrastructure and what access those identities should receive. When a vulnerability affects the authentication mechanisms of the platform responsible for enforcing those decisions, it creates a potentially serious trust-boundary failure. Cisco identifies the root cause of CVE-2026-76460 as insufficient authentication control on an API endpoint, allowing an unauthenticated attacker to send a specially crafted request and bypass authentication associated with the web-based management interface. The vulnerability carries a maximum CVSS score of 10.0, reflecting the serious potential consequences of compromising a platform that performs such a privileged role within enterprise network architecture.

The authentication-bypass mechanism demonstrates why administrative APIs deserve the same security scrutiny as traditional management interfaces. Modern enterprise applications increasingly expose management functionality through APIs because automation, orchestration and integration platforms need programmatic access to configuration and operational controls. Those APIs can become attractive attack surfaces when developers assume that authentication is already enforced elsewhere in the application or fail to apply access-control checks consistently to every endpoint. An API endpoint that unintentionally permits unauthenticated access can undermine the protections surrounding an otherwise secure management interface, creating an alternative route to functionality that should be available only to authorized administrators. The critical lesson is that authentication and authorization must be enforced independently and consistently at every sensitive interface rather than depending on assumptions about how users normally reach administrative functions.

The consequences of unauthorized access to an identity management platform can extend beyond the initial application, depending on the access obtained and the configuration of the affected environment. Cisco ISE may maintain authentication policies, device information, administrative configurations and integrations with network infrastructure, making it a potentially valuable target for attackers seeking insight into an organisation's access-control architecture. Successful exploitation could expose sensitive management functionality and create opportunities for further compromise, although the public advisory does not establish that every attacker can automatically obtain full control over all connected switches, firewalls or endpoints. Security analysis should therefore distinguish the confirmed authentication-bypass vulnerability from additional consequences that depend on the privileges obtained, the deployment architecture and the attacker's subsequent actions.

Cisco's confirmation of active exploitation makes the situation particularly urgent because the vulnerability has moved beyond theoretical research. The company states that it is aware of malicious exploitation and has released corrective software, while also confirming that there are no workarounds that fully address the vulnerability. This leaves organisations with a clear remediation requirement: identify affected ISE and ISE-PIC deployments, determine the installed software releases and apply the appropriate vendor updates. Cisco identifies the first fixed releases as 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. Administrators should verify the applicable release information across every deployment rather than assuming that updating one management node automatically protects the entire environment.

The Acronis vulnerability presents a different attack scenario, but its location within backup infrastructure makes it equally important from a security architecture perspective. CVE-2026-87886 is a high-severity local privilege-escalation vulnerability caused by insecure file permissions in Acronis Backup integrations used with cPanel, WHM and Plesk on Linux systems. An attacker who already possesses low-privileged access to a vulnerable system may be able to increase their privileges and perform unauthorized actions or execute code with elevated permissions. Unlike the Cisco vulnerability, this weakness is not described as an unauthenticated remote authentication bypass, and successful exploitation requires an existing foothold. Nevertheless, that prerequisite does not make the issue insignificant because privilege escalation is frequently the mechanism through which attackers transform limited access into a much more serious server compromise.

Hosting environments are particularly sensitive to local privilege-escalation vulnerabilities because a single server may support numerous websites, databases, email services and customer accounts. Attackers may initially obtain access through compromised hosting credentials, vulnerable web applications or malicious scripts operating under restricted service accounts, but those limitations are intended to prevent one compromised account from affecting the entire system. A privilege-escalation vulnerability can weaken those isolation boundaries, potentially allowing the attacker to access resources or perform operations outside the original account's permissions. The precise consequences depend on the privileges obtained and the server configuration, but the broader concern is that an initial compromise that should have remained limited may become a much larger incident.

The fact that the vulnerability affects backup integrations introduces an additional concern because backup software often needs access to substantial quantities of sensitive information to perform its legitimate recovery functions. Backup components may interact with application files, databases, configuration information and recovery repositories, making them attractive targets for attackers who want to steal data, interfere with recovery or establish additional access. This does not establish that CVE-2026-87886 has been used to destroy backups or deploy ransomware, because Acronis has not publicly disclosed those outcomes, but it illustrates why privileged backup infrastructure requires careful isolation and monitoring. The systems responsible for restoring an organisation after an incident should not become unnecessarily broad trust bridges into the production environment.

Acronis reports that exploitation has been detected in limited, targeted attacks, although the company has not publicly identified the attackers or disclosed the full circumstances of the incidents. The affected software includes Acronis Backup plugin for cPanel and WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638. Acronis has released corrective updates and advises users to install them immediately. The absence of detailed public exploit information should not be interpreted as evidence that the vulnerability is harmless, particularly when the vendor has confirmed exploitation, but defenders should also avoid describing the activity as widespread mass exploitation without supporting evidence.

The combination of these two vulnerabilities in a single CISA alert reinforces why vulnerability management must consider the operational role of affected systems rather than relying entirely on numerical severity scores. Cisco ISE is a critical access-control platform, while Acronis Backup integrations form part of an organisation's recovery and hosting infrastructure. A compromise affecting either type of system can create consequences that differ substantially from those associated with an ordinary user application. Security teams should therefore assess the potential impact according to the privileges, credentials, data and network relationships available to the affected product, while preserving the distinction between the different exploitation requirements of the two CVEs.

There is also an important lesson about vulnerability chaining, although no connection between these two exploitation campaigns has been established. Attackers frequently combine an initial access technique with a separate privilege-escalation vulnerability to achieve greater control over a compromised environment. An exposed application weakness might provide limited command execution, while another flaw could allow the attacker to escape that restricted context. The Acronis issue demonstrates why local privilege escalation remains relevant even when it cannot be exploited directly by an unauthenticated internet user. However, the Cisco and Acronis vulnerabilities should not be presented as a documented exploit chain, because they affect different products and the available evidence does not show that attackers are combining them.

The incident-response implications also differ from the immediate patching requirements. Installing the corrected software prevents future exploitation through the identified vulnerable code, but it cannot establish whether an attacker already obtained access before remediation. Organisations operating vulnerable Cisco ISE systems should review relevant authentication and administrative activity, investigate unusual API requests and examine unexpected configuration changes or outbound connections where appropriate. Organisations operating affected Acronis integrations should review authentication records, privilege changes, unusual process execution, modifications to backup configuration and other signs of unexpected administrative activity. The investigation should follow vendor guidance and the evidence available in the environment rather than assuming that identical indicators of compromise will apply to both vulnerabilities.

Independent logging becomes particularly important when the affected systems themselves may have been compromised. Security appliances and backup platforms should forward relevant events to separate logging infrastructure so that investigators can reconstruct activity even if local records are incomplete or have been altered. Network telemetry from adjacent firewalls, DNS services and monitoring platforms may help identify unusual communication patterns or access attempts that would otherwise be difficult to establish from the compromised host alone. This reinforces a broader architectural principle that critical security infrastructure should not be the sole custodian of evidence about its own operation.

Network segmentation provides another valuable defensive layer. Cisco ISE management interfaces should be accessible only through appropriate administrative paths, while access to backup management systems should similarly be restricted to authorized personnel and networks. These controls cannot replace vendor patches, but they can limit exposure and reduce opportunities for attackers to reach sensitive functionality. Production hosting systems should not automatically have unrestricted administrative access to backup repositories, just as identity-management platforms should not possess unnecessary connectivity to unrelated network segments. Each privileged component should have only the access required for its legitimate operational role.

Credential management should also form part of the response when compromise is confirmed. Identity platforms and backup systems may maintain credentials, certificates, API keys or integration secrets that attackers could potentially access depending on the privileges obtained. If an investigation establishes that sensitive authentication material was exposed, affected credentials should be revoked or rotated and related access should be reviewed. Replacing vulnerable software without addressing stolen credentials can leave an attacker with an alternative access mechanism even after the original vulnerability has been closed.

The broader cybersecurity lesson from these two CVEs is that trusted infrastructure requires its own independent layers of protection. A product designed to enforce authentication is not automatically immune to authentication vulnerabilities, and software responsible for backup and recovery is not automatically protected against privilege escalation. Organisations should evaluate security products and infrastructure components as potential attack surfaces in their own right, maintaining accurate inventories, restricting administrative exposure, enforcing least privilege, applying emergency updates and monitoring their behaviour continuously.

Ultimately, CISA's addition of CVE-2026-76460 and CVE-2026-87886 demonstrates that identity and recovery infrastructure must be included among an organisation's most carefully protected assets. The immediate requirement is to identify affected deployments, apply the relevant Cisco and Acronis fixes and investigate systems where evidence or exposure suggests that exploitation may already have occurred. The longer-term requirement is to build an architecture in which failure of one trusted component does not automatically provide unrestricted access to the rest of the enterprise. Authentication systems must remain protected even while enforcing access for others, backup systems must remain isolated even while accessing production data, and both must be monitored as critically as the systems they are intended to protect. When attackers begin exploiting vulnerabilities in the infrastructure responsible for access control and recovery, cybersecurity resilience depends on recognising that the security controls themselves can become targets and designing the environment accordingly.


CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exploited vulnerability not c

Source: CISA Adds Two Known Exploited Vulnerabilities to Catalog via CISA Advisories — published 16 Sep 2026.