highOther

CISA KEV Catalog Addition: Cisco ISE and Acronis Backup Actively Exploited Vulnerabilities

First seen Sep 17, 2026 · Updated Sep 17, 2026

cisakevknown-exploited-vulnerabilitiesciscoiseacronisprivilege-escalationdefault-permissionsfederalbod-26-04patch-management

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a Cisco Identity Services Engine (ISE) privileged API abuse flaw and an Acronis Backup incorrect default permissions vulnerability. Both are confirmed to be under active exploitation in the wild, and FCEB agencies are required under BOD 26-04 to remediate them on an accelerated timeline. All organizations, including those running identity management or backup infrastructure supporting AI agent deployments, are urged to prioritize patching.

Technical Analysis

CVE-2026-76460 affects Cisco Identity Services Engine (ISE) and involves incorrect use of privileged APIs, potentially allowing an attacker to escalate privileges or perform unauthorized administrative actions on the ISE platform, which is commonly used for network access control and identity policy enforcement. CVE-2026-87886 affects Acronis Backup and stems from incorrect default permissions, which could allow local or network-adjacent attackers to access, modify, or exfiltrate backup data without proper authorization. Both vulnerabilities have confirmed evidence of active exploitation, meeting CISA's criteria for KEV inclusion, and are particularly dangerous on publicly exposed assets where they could grant significant post-exploitation control. Organizations running Cisco ISE for network authentication of AI agent infrastructure, or using Acronis Backup to protect model artifacts, vector stores, RAG data pipelines, or agent configuration/credential stores, face risk of unauthorized access, data tampering, or credential exposure that could compromise agent framework integrity and the secrets agents rely on for tool use.

Affected Systems

Cisco Identity Services Engine (ISE) - versions affected by CVE-2026-76460; Acronis Backup - versions affected by CVE-2026-87886 with incorrect default permissions configurations

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this CISA alert; organizations should monitor Cisco ISE admin API logs and Acronis Backup access/permission audit logs for anomalous activity

Remediation Steps

  1. 1

    Apply vendor patches

    Immediately apply the latest security patches from Cisco for ISE (CVE-2026-76460) and from Acronis for Backup (CVE-2026-87886) as specified in vendor advisories.

  2. 2

    Prioritize per BOD 26-04

    FCEB agencies must remediate these KEV Catalog entries within CISA-mandated timelines, especially on publicly exposed assets granting full post-exploitation control.

  3. 3

    Review permissions configuration

    Audit Acronis Backup deployments for default permission settings and reconfigure to enforce least-privilege access controls.

  4. 4

    Audit privileged API access

    Review Cisco ISE logs for evidence of unauthorized privileged API calls and restrict API access to only necessary administrative accounts.

  5. 5

    Compromise assessment

    Per BOD 26-04 guidance, check whether systems were compromised prior to patch application, especially for internet-facing instances.

  6. 6

    Extend to non-federal environments

    Non-FCEB organizations, including those supporting AI agent infrastructure, should adopt the same risk-based prioritization and patch these KEV entries promptly.

CVE / Advisory IDs

CVE-2026-76460CVE-2026-87886

Industries Most Exposed

governmentfederaltechnologycritical-infrastructureall-sectors-using-affected-products

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.