This day 02:02 06:02 10:02 14:03 18:03 22:04
⚠ exploit status: CVE-2026-58704 · KEV CVE-2026-76460 · KEV CVE-2026-87886 · KEV
High  2026-09-17 06:02Z · last 4h · 3 findings · glm-5.2:cloud

Threat Brief — 2026-09-17

Executive summary

CISA has added three privilege-escalation vulnerabilities to its Known Exploited Vulnerabilities catalog today: Acronis Backup (cPanel/Plesk plugin), Cisco Identity Services Engine, and Google Pixel cellular modem. All three are now confirmed exploited in the wild. The Cisco ISE entry is newly disclosed with no prior reporting; the Acronis and Pixel entries formalise KEV listing for vulnerabilities already under active exploitation reported earlier this week.

Top items

Themes

All three KEV additions today are privilege-escalation vulnerabilities spanning distinct attack surfaces — network access control appliances (Cisco ISE), hosting control panels (Acronis/cPanel), and mobile device firmware (Pixel modem). The common thread is that attackers are leveraging logic and permission-model flaws rather than memory-safety bugs, and all three have progressed from vendor advisory to confirmed in-the-wild exploitation within days.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db