CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and Acronis Backup Privilege Escalation (CVE-2026-87886)

CISA KEV Catalog Addition (TL-2026-2542) is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-16. It has no confirmed attribution, affects Cisco Identity Services Engine (ISE) / ISE Passive Identity Connector, references 2 CVEs (CVE-2026-76460, CVE-2026-87886), maps to 9 MITRE ATT&CK techniques (T1005, T1059, T1078), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2542

Threat ID
TL-2026-2542
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-16
Last reviewed
2026-09-16
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, web hosting, managed service providers, enterprise network infrastructure
Target regions
united states of america, Global
Detection rules
9
Indicators of compromise
9

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 2026-09-16: CVE-2026-76460, a CVSS 10.0 unauthenticated API authentication-bypass flaw in Cisco Identity Services Engine (ISE) and ISE-PIC granting root-level command execution, and CVE-2026-87886, a CVSS 7.8 insecure-file-permissions flaw in the Acronis Backup plugin for cPanel & WHM and Plesk enabling local privilege escalation on shared-hosting and MSP Linux servers. Both carry a BOD 26-04 federal remediation deadline of 2026-09-19.

How CISA KEV Catalog Addition works

On September 16, 2026, CISA added CVE-2026-76460 and CVE-2026-87886 to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed evidence of active, in-the-wild exploitation, triggering a Binding Operational Directive 26-04 remediation deadline of September 19, 2026 for Federal Civilian Executive Branch agencies, who must also check publicly exposed instances for prior compromise.

CVE-2026-76460 (CWE-648, Incorrect Use of Privileged APIs) affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) releases 3.1 through 3.5 (and unsupported 3.0), plus ISE-PIC 3.4.0/3.5.0. Per Cisco's advisory (cisco-sa-ISE-ABP-VNSW7Tn5) and its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), insufficient authentication control on an API endpoint behind the ISE-Kong API gateway lets an unauthenticated, remote attacker with no prerequisites send a crafted request to bypass the web-based management interface entirely and execute commands with root privileges. Cisco PSIRT confirmed active exploitation and noted attackers can erase log entries to conceal their actions; defenders are told to hunt for a 'dummyuser' account in the API gateway access log (`./ise/logs/apigateway/access.log..gz` when extracted from a support bundle) and to cross-check external network/firewall logs for unexpected data transfers as a secondary compromise indicator. Cisco disclosed that CVE-2026-76460 was identified while resolving a Technical Assistance Center (TAC) support case, confirming at least one enterprise environment was already compromised before the vulnerability was publicly reported. No workaround exists beyond infrastructure ACLs restricting management-plane access — patching (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) is mandatory. Because ISE is the Network Access Control (NAC) platform enforcing 802.1X authentication, device profiling, and posture assessment across wired, wireless, and VPN connections, compromise of an exposed instance can cascade into broader network-wide access-control failure; media reporting noted the CVE was disclosed alongside other, separately tracked Cisco ISE security advisories published the same day, underscoring identity infrastructure as an expanding attack surface (out of scope for this threat record beyond that context).

CVE-2026-87886 (CWE-276, Incorrect Default Permissions, CVSS 3.1 base score 7.8) affects the Acronis Backup plugin for cPanel & WHM (builds before 1.9.3.1021, fixed in 1.9.3 HF3) and the Acronis Backup extension for Plesk (builds before 1.8.11.638, fixed in 1.8.11). Insecure default file permissions on the Linux-based backup component allow an authenticated, low-privileged local attacker to escalate privileges without user interaction and without any special conditions beyond the attacker's control (low attack complexity). Acronis confirmed exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM deployments — based on a single customer report — while Plesk deployments have not been observed exploited; the company withheld technical root-cause and post-escalation attacker-behavior detail specifically to give administrators a patching window before publishing more. Reporting describes a plausible multi-stage chain — initial access via a compromised hosting account, weak credentials, a vulnerable web application, or a web shell, followed by abuse of the vulnerable Acronis component to escalate privileges — with impact in shared-hosting/MSP environments potentially extending to other customers' backup data, system files, and control-panel resources on the same host; because the vulnerable component is itself backup software, a root/administrative foothold gained through it can also be leveraged to delete, corrupt, or disable backup jobs and recovery points, inhibiting incident recovery for affected tenants.

MITRE ATT&CK techniques used in TL-2026-2542

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1078.001 Default Accounts; T1505.003 Web Shell

defense-impairment

T1222.002 Linux and Mac Permissions; T1685.006 Clear Linux or Mac System Logs

Impact

T1490 Inhibit System Recovery

Affected products and versions in CISA KEV Catalog Addition

  • Cisco — Identity Services Engine (ISE) / ISE Passive Identity Connector (ISE-PIC)
    Vulnerable versions: 3.0 (end of support); 3.1 through 3.1 Patch 11; 3.2 through 3.2 Patch 10; 3.3 through 3.3 Patch 11; 3.4 through 3.4 Patch 6; 3.5 through 3.5 Patch 3
    Fixed in: 3.1 Patch 12; 3.2 Patch 11; 3.3 Patch 12; 3.4 Patch 7; 3.5 Patch 4
  • Acronis — Backup plugin for cPanel & WHM
    Vulnerable versions: builds before 1.9.3.1021
    Fixed in: 1.9.3 HF3
  • Acronis — Backup extension for Plesk
    Vulnerable versions: builds before 1.8.11.638
    Fixed in: 1.8.11

Remediation for CISA KEV Catalog Addition

Patches

  • Cisco ISE/ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4
  • Acronis Backup plugin for cPanel & WHM 1.9.3 HF3
  • Acronis Backup extension for Plesk 1.8.11

Immediate actions

  • Apply Cisco ISE/ISE-PIC patches (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) or take internet-exposed management interfaces offline per the BOD 26-04 2026-09-19 deadline
  • Upgrade Acronis Backup plugin for cPanel & WHM to 1.9.3 HF3 and Acronis Backup extension for Plesk to 1.8.11 immediately on all Linux hosts
  • Review Cisco ISE access.log for the 'dummyuser' account and any other unrecognized local accounts or evidence of log tampering
  • Audit Acronis-related files/directories, authentication logs, shell activity, and cPanel/Plesk account events for unauthorized privilege changes

Workarounds

  • No official workaround for CVE-2026-76460; infrastructure ACLs limiting management-plane traffic only reduce exposure
  • No official workaround for CVE-2026-87886; installing the patched build is the only vendor-confirmed remediation

Longer-term hardening

  • Restrict management-plane access to Cisco ISE with infrastructure ACLs, since no vendor workaround exists for CVE-2026-76460
  • Migrate any remaining Cisco ISE 3.0 (end-of-support) deployments to a currently patched release train
  • Harden default file/directory permissions on backup and hosting-control-panel components to close CWE-276-class weaknesses
  • Adopt continuous KEV-catalog monitoring and risk-based vulnerability management consistent with BOD 26-04
  • Per the CISA KEV catalog required action, apply vendor mitigations per BOD 26-04 guidance and discontinue use of the affected product if mitigations are unavailable
  • Verify integrity and availability of backup jobs/recovery points on any host running the vulnerable Acronis component, given a root foothold gained through it could be used to inhibit recovery

CVEs associated with CISA KEV Catalog Addition

CVE-2026-76460, CVE-2026-87886

Weaknesses (CWE) in CISA KEV Catalog Addition

CWE-648, CWE-276

Timeline of CISA KEV Catalog Addition

  • Acronis ships patched builds (Backup plugin for cPanel & WHM 1.9.3 HF3; Backup extension for Plesk 1.8.11) ahead of public disclosure of CVE-2026-87886.
  • Security media (BleepingComputer, SecurityWeek, Help Net Security, Cyberpress, SecurityOnline) report on both vulnerabilities and the KEV catalog addition.
  • CISA's alert invokes Binding Operational Directive 26-04, directing FCEB agencies to prioritize remediation on publicly exposed assets and check for prior compromise.
  • CISA adds both CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities catalog based on confirmed evidence of active exploitation.
  • Cisco publishes advisory cisco-sa-ISE-ABP-VNSW7Tn5 for CVE-2026-76460 (CVSS 10.0, CWE-648), with PSIRT confirming active exploitation enabling unauthenticated root-level command execution on ISE.
  • Acronis publishes advisory SEC-10986 disclosing CVE-2026-87886 (CVSS 7.8, CWE-276) and confirms limited, targeted in-the-wild exploitation against cPanel & WHM deployments; Plesk not observed exploited.
  • Cisco discloses that CVE-2026-76460 was identified during resolution of a Technical Assistance Center (TAC) support case, confirming at least one enterprise ISE environment was already compromised before the vulnerability was publicly reported.
  • BOD 26-04 remediation deadline: Federal Civilian Executive Branch agencies must have patched or mitigated both CVE-2026-76460 and CVE-2026-87886.

Sources cited for CISA KEV Catalog Addition

More in vulnerability

Detection coverage for TL-2026-2542

As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2542 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats