CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and Acronis Backup Privilege Escalation (CVE-2026-87886)
CISA KEV Catalog Addition (TL-2026-2542) is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-16. It has no confirmed attribution, affects Cisco Identity Services Engine (ISE) / ISE Passive Identity Connector, references 2 CVEs (CVE-2026-76460, CVE-2026-87886), maps to 9 MITRE ATT&CK techniques (T1005, T1059, T1078), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2542
- Threat ID
- TL-2026-2542
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-16
- Last reviewed
- 2026-09-16
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, web hosting, managed service providers, enterprise network infrastructure
- Target regions
- united states of america, Global
- Detection rules
- 9
- Indicators of compromise
- 9
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 2026-09-16: CVE-2026-76460, a CVSS 10.0 unauthenticated API authentication-bypass flaw in Cisco Identity Services Engine (ISE) and ISE-PIC granting root-level command execution, and CVE-2026-87886, a CVSS 7.8 insecure-file-permissions flaw in the Acronis Backup plugin for cPanel & WHM and Plesk enabling local privilege escalation on shared-hosting and MSP Linux servers. Both carry a BOD 26-04 federal remediation deadline of 2026-09-19.
How CISA KEV Catalog Addition works
On September 16, 2026, CISA added CVE-2026-76460 and CVE-2026-87886 to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed evidence of active, in-the-wild exploitation, triggering a Binding Operational Directive 26-04 remediation deadline of September 19, 2026 for Federal Civilian Executive Branch agencies, who must also check publicly exposed instances for prior compromise.
CVE-2026-76460 (CWE-648, Incorrect Use of Privileged APIs) affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) releases 3.1 through 3.5 (and unsupported 3.0), plus ISE-PIC 3.4.0/3.5.0. Per Cisco's advisory (cisco-sa-ISE-ABP-VNSW7Tn5) and its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), insufficient authentication control on an API endpoint behind the ISE-Kong API gateway lets an unauthenticated, remote attacker with no prerequisites send a crafted request to bypass the web-based management interface entirely and execute commands with root privileges. Cisco PSIRT confirmed active exploitation and noted attackers can erase log entries to conceal their actions; defenders are told to hunt for a 'dummyuser' account in the API gateway access log (`./ise/logs/apigateway/access.log..gz` when extracted from a support bundle) and to cross-check external network/firewall logs for unexpected data transfers as a secondary compromise indicator. Cisco disclosed that CVE-2026-76460 was identified while resolving a Technical Assistance Center (TAC) support case, confirming at least one enterprise environment was already compromised before the vulnerability was publicly reported. No workaround exists beyond infrastructure ACLs restricting management-plane access — patching (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) is mandatory. Because ISE is the Network Access Control (NAC) platform enforcing 802.1X authentication, device profiling, and posture assessment across wired, wireless, and VPN connections, compromise of an exposed instance can cascade into broader network-wide access-control failure; media reporting noted the CVE was disclosed alongside other, separately tracked Cisco ISE security advisories published the same day, underscoring identity infrastructure as an expanding attack surface (out of scope for this threat record beyond that context).
CVE-2026-87886 (CWE-276, Incorrect Default Permissions, CVSS 3.1 base score 7.8) affects the Acronis Backup plugin for cPanel & WHM (builds before 1.9.3.1021, fixed in 1.9.3 HF3) and the Acronis Backup extension for Plesk (builds before 1.8.11.638, fixed in 1.8.11). Insecure default file permissions on the Linux-based backup component allow an authenticated, low-privileged local attacker to escalate privileges without user interaction and without any special conditions beyond the attacker's control (low attack complexity). Acronis confirmed exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM deployments — based on a single customer report — while Plesk deployments have not been observed exploited; the company withheld technical root-cause and post-escalation attacker-behavior detail specifically to give administrators a patching window before publishing more. Reporting describes a plausible multi-stage chain — initial access via a compromised hosting account, weak credentials, a vulnerable web application, or a web shell, followed by abuse of the vulnerable Acronis component to escalate privileges — with impact in shared-hosting/MSP environments potentially extending to other customers' backup data, system files, and control-panel resources on the same host; because the vulnerable component is itself backup software, a root/administrative foothold gained through it can also be leveraged to delete, corrupt, or disable backup jobs and recovery points, inhibiting incident recovery for affected tenants.
MITRE ATT&CK techniques used in TL-2026-2542
Collection
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1078.001 Default Accounts; T1505.003 Web Shell
defense-impairment
T1222.002 Linux and Mac Permissions; T1685.006 Clear Linux or Mac System Logs
Impact
Affected products and versions in CISA KEV Catalog Addition
- Cisco — Identity Services Engine (ISE) / ISE Passive Identity Connector (ISE-PIC)
Vulnerable versions: 3.0 (end of support); 3.1 through 3.1 Patch 11; 3.2 through 3.2 Patch 10; 3.3 through 3.3 Patch 11; 3.4 through 3.4 Patch 6; 3.5 through 3.5 Patch 3
Fixed in: 3.1 Patch 12; 3.2 Patch 11; 3.3 Patch 12; 3.4 Patch 7; 3.5 Patch 4 - Acronis — Backup plugin for cPanel & WHM
Vulnerable versions: builds before 1.9.3.1021
Fixed in: 1.9.3 HF3 - Acronis — Backup extension for Plesk
Vulnerable versions: builds before 1.8.11.638
Fixed in: 1.8.11
Remediation for CISA KEV Catalog Addition
Patches
- Cisco ISE/ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4
- Acronis Backup plugin for cPanel & WHM 1.9.3 HF3
- Acronis Backup extension for Plesk 1.8.11
Immediate actions
- Apply Cisco ISE/ISE-PIC patches (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) or take internet-exposed management interfaces offline per the BOD 26-04 2026-09-19 deadline
- Upgrade Acronis Backup plugin for cPanel & WHM to 1.9.3 HF3 and Acronis Backup extension for Plesk to 1.8.11 immediately on all Linux hosts
- Review Cisco ISE access.log for the 'dummyuser' account and any other unrecognized local accounts or evidence of log tampering
- Audit Acronis-related files/directories, authentication logs, shell activity, and cPanel/Plesk account events for unauthorized privilege changes
Workarounds
- No official workaround for CVE-2026-76460; infrastructure ACLs limiting management-plane traffic only reduce exposure
- No official workaround for CVE-2026-87886; installing the patched build is the only vendor-confirmed remediation
Longer-term hardening
- Restrict management-plane access to Cisco ISE with infrastructure ACLs, since no vendor workaround exists for CVE-2026-76460
- Migrate any remaining Cisco ISE 3.0 (end-of-support) deployments to a currently patched release train
- Harden default file/directory permissions on backup and hosting-control-panel components to close CWE-276-class weaknesses
- Adopt continuous KEV-catalog monitoring and risk-based vulnerability management consistent with BOD 26-04
- Per the CISA KEV catalog required action, apply vendor mitigations per BOD 26-04 guidance and discontinue use of the affected product if mitigations are unavailable
- Verify integrity and availability of backup jobs/recovery points on any host running the vulnerable Acronis component, given a root foothold gained through it could be used to inhibit recovery
CVEs associated with CISA KEV Catalog Addition
Weaknesses (CWE) in CISA KEV Catalog Addition
CWE-648, CWE-276
Timeline of CISA KEV Catalog Addition
- Acronis ships patched builds (Backup plugin for cPanel & WHM 1.9.3 HF3; Backup extension for Plesk 1.8.11) ahead of public disclosure of CVE-2026-87886.
- Security media (BleepingComputer, SecurityWeek, Help Net Security, Cyberpress, SecurityOnline) report on both vulnerabilities and the KEV catalog addition.
- CISA's alert invokes Binding Operational Directive 26-04, directing FCEB agencies to prioritize remediation on publicly exposed assets and check for prior compromise.
- CISA adds both CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities catalog based on confirmed evidence of active exploitation.
- Cisco publishes advisory cisco-sa-ISE-ABP-VNSW7Tn5 for CVE-2026-76460 (CVSS 10.0, CWE-648), with PSIRT confirming active exploitation enabling unauthenticated root-level command execution on ISE.
- Acronis publishes advisory SEC-10986 disclosing CVE-2026-87886 (CVSS 7.8, CWE-276) and confirms limited, targeted in-the-wild exploitation against cPanel & WHM deployments; Plesk not observed exploited.
- Cisco discloses that CVE-2026-76460 was identified during resolution of a Technical Assistance Center (TAC) support case, confirming at least one enterprise ISE environment was already compromised before the vulnerability was publicly reported.
- BOD 26-04 remediation deadline: Federal Civilian Executive Branch agencies must have patched or mitigated both CVE-2026-76460 and CVE-2026-87886.
Sources cited for CISA KEV Catalog Addition
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- CISA Known Exploited Vulnerabilities Catalog (JSON feed)
- Cisco Security Advisory: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (cisco-sa-ISE-ABP-VNSW7Tn5)
- Acronis Advisory: Local privilege escalation due to insecure file permissions (SEC-10986)
- Acronis warns of actively exploited flaw in its cPanel backup plugin
- Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
- Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
- Acronis Backup Plugin Vulnerability in cPanel and Plesk Exploited in the Wild
- CVE-2026-76460 (CVSS 10): Cisco ISE Vulnerability Exploited in the Wild
- CVE-2026-76460: Cisco Identity Services Engine Software vulnerability profile
- NVD - CVE-2026-76460 Detail
- The Gatekeeper Is the Door: Cisco ISE's Nine-CVE Disclosure and the Identity Infrastructure Attack Surface
More in vulnerability
- CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively Exploited
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract Argument Injection
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE
Detection coverage for TL-2026-2542
As of 2026-09-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2542 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.