Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities (KEV) catalog, indicating that they are being actively exploited by malicious actors. This move highlights the growing concern for cybersecurity and the need for organizations to address these vulnerabilities to protect their networks and systems from exploitation. With the U.S. CISA ordering federal agencies to fix the flaws by specific deadlines, it is essential for organizations to stay informed and take prompt action to address these vulnerabilities and reduce the risk of being targeted by these malicious actors.
CISA has added Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities (KEV) catalog. The KEV catalog highlights vulnerabilities that are being actively exploited by attackers, indicating targeted malicious activity. The vulnerabilities include authentication bypass, local privilege escalation, and improper authorization flaws. Cisco, Acronis, and Google have released security updates to address these vulnerabilities, but they have already been exploited in the wild. Organizations are urged to address these vulnerabilities immediately to reduce the risk of exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities (KEV) catalog. This move is a significant concern for cybersecurity experts and organizations around the world. The KEV catalog is a list of known vulnerabilities that are being actively exploited by attackers, and adding these three flaws to the list indicates that they are being targeted by malicious actors.
The first flaw, CVE-2026-76460, is an authentication bypass vulnerability affecting the Cisco Identity Services Engine (ISE). This vulnerability allows an unauthenticated remote attacker to gain unauthorized access to the affected system through its web-based management interface. The Cisco PSIRT is aware of active exploitation of this vulnerability, and the company strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
The second flaw, CVE-2026-87886, is a local privilege escalation vulnerability in Acronis Backup. This vulnerability is caused by insecure file permissions, allowing a local attacker with limited privileges to manipulate files used by the backup service and potentially execute code with elevated, root-level privileges. Acronis reported exploitation in the wild in limited, targeted attacks.
The third flaw, CVE-2026-58704, is an Improper Authorization vulnerability in the Google Pixel cellular modem. This vulnerability allows an attacker to escalate privileges remotely without requiring user interaction, making it a significant concern for cybersecurity experts. Google has released a security update to address this vulnerability, but it has already been exploited in the wild.
These additions to the KEV catalog highlight the growing concern for cybersecurity in the wake of these vulnerabilities. The fact that these flaws are being actively exploited by attackers indicates that they are being targeted by malicious actors, and organizations need to take immediate action to address these vulnerabilities.
The U.S. CISA has ordered federal agencies to fix the GitLab and ConnectWise flaws by September 14, 2026, and the remaining JFrog Artifactory issues must be addressed by September 19, 2026. Experts also recommend that private organizations review the KEV catalog and address the vulnerabilities in their infrastructure.
The addition of these flaws to the KEV catalog serves as a reminder of the importance of cybersecurity and the need for organizations to stay vigilant and proactive in addressing vulnerabilities. By staying informed and taking prompt action, organizations can reduce the risk of being targeted by these malicious actors and protect their networks and systems from exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Acronis-Backup-Cisco-ISE-and-Google-Pixel-Flaws-to-its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml
https://securityaffairs.com/199239/security/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://securityaffairs.com/199239/uncategorized/u-s-cisa-adds-acronis-backup-cisco-ise-and-google-pixel-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://nvd.nist.gov/vuln/detail/CVE-2026-76460
https://www.cvedetails.com/cve/CVE-2026-76460/
https://nvd.nist.gov/vuln/detail/CVE-2026-87886
https://www.cvedetails.com/cve/CVE-2026-87886/
https://nvd.nist.gov/vuln/detail/CVE-2026-58704
https://www.cvedetails.com/cve/CVE-2026-58704/
Published: Thu Sep 17 06:33:02 2026 by llama3.2 3B Q4_K_M