Threat Brief — 2026-09-17
Executive summary
CISA has added three privilege-escalation vulnerabilities to its Known Exploited Vulnerabilities catalog today: Acronis Backup (cPanel/Plesk plugin), Cisco Identity Services Engine, and Google Pixel cellular modem. All three are now confirmed exploited in the wild. The Cisco ISE entry is newly disclosed with no prior reporting; the Acronis and Pixel entries formalise KEV listing for vulnerabilities already under active exploitation reported earlier this week.
Top items
- CVE-2026-76460KEV — Cisco ISE privileged API misuse, now in CISA KEV. Cisco Identity Services Engine and ISE Passive Identity Connector contain an incorrect use of privileged APIs vulnerability allowing privilege escalation. CISA has added it to the KEV catalog, confirming active exploitation. This is a new finding with no prior public reporting. (src: CISA:KEV)
- CVE-2026-87886KEV — Acronis Backup cPanel/Plesk plugin LPE, now in CISA KEV. Incorrect default permissions in the Acronis Backup plugin for cPanel & WHM and extension for Plesk allow privilege escalation. This vulnerability was first reported as actively exploited on 2026-09-15 by BleepingComputer; the new development is its formal addition to the CISA KEV catalog. (src: CISA:KEV)
- CVE-2026-58704KEV — Google Pixel modem improper authorization, now in CISA KEV. A logic error in the Pixel cellular modem allows attackers to bypass permission checks and escalate privileges. This was first reported as actively exploited on 2026-09-16 by BleepingComputer; the new development is its formal addition to the CISA KEV catalog. (src: CISA:KEV)
Themes
All three KEV additions today are privilege-escalation vulnerabilities spanning distinct attack surfaces — network access control appliances (Cisco ISE), hosting control panels (Acronis/cPanel), and mobile device firmware (Pixel modem). The common thread is that attackers are leveraging logic and permission-model flaws rather than memory-safety bugs, and all three have progressed from vendor advisory to confirmed in-the-wild exploitation within days.
