Critical Authentication Bypass in Cisco ISE (CVE‑2026‑76460) and Related High‑Severity Flaws Added to CISA KEV Catalog
What It Is – CISA has placed three actively‑exploited vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog: a CVSS 10.0 authentication‑bypass flaw in Cisco Identity Services Engine (ISE), an insecure‑default‑permissions issue in Acronis Backup (CVE‑2026‑87886), and an improper‑authorization bug in Google Pixel’s cellular modem (CVE‑2026‑58704).
Exploitability – Cisco ISE’s API can be accessed without any credentials; the Cisco PSIRT confirms active exploitation. Acronis and Google flaws have also been observed in the wild, with attackers leveraging local privilege escalation or remote modem abuse.
Affected Products – Cisco ISE (network access control), Acronis Backup (cPanel/WHM and Plesk plugins), Google Pixel smartphones (cellular modem firmware).
Why It Matters for Trust & Control Assurance
- Access‑control hygiene – The Cisco flaw shows how missing authentication checks on privileged APIs can break the core “only authorized users may act” control, a requirement across most frameworks.
- Continuous patch assurance – Demonstrating that you have a documented, auditable process for applying vendor patches (Cisco, Acronis, Google) provides concrete evidence of due‑diligence.
- Defensible audit trail – Logging API calls and privilege‑escalation attempts creates traceable evidence that can be presented during compliance reviews or third‑party risk assessments.
Recommended Actions
- Deploy the Cisco ISE security update immediately; verify the patched version through inventory tooling.
- Review and tighten file‑system permissions for Acronis Backup plugins; apply the vendor‑released fix and re‑audit privileged directories.
- Push the September 2026 Pixel security update to all managed devices; confirm the modem firmware version.
- Enable comprehensive logging for privileged API endpoints and backup service actions; retain logs for at least 90 days.
- Incorporate these patches into your continuous vulnerability‑management pipeline to ensure future exposures are caught early.
Source: Security Affairs – CISA adds Acronis, Cisco, Google flaws to KEV catalog