Cisco says attackers are already exploiting a flaw in Identity Services Engine, the product enterprises use to decide which users and devices are allowed onto their networks. It carries a CVSS base score of 10.0, the highest the scale goes, and Cisco's advisory states plainly that the company is aware of active exploitation.
CISA added it to the federal Known Exploited Vulnerabilities catalog on 16 September, alongside a second flaw in Acronis Backup. Federal civilian agencies have until 19 September to act on both.
A gatekeeper that can be walked around
According to Cisco's advisory, CVE-2026-76460 lets an unauthenticated, remote attacker gain unauthorized access to an affected device by bypassing the web-based management interface. Releases 3.1, 3.2, 3.3, 3.4 and 3.5 of both ISE and the ISE Passive Identity Connector are affected. Cisco published the advisory on 16 September, the same day the bug reached the federal catalog.
The two organizations do not describe it the same way. Cisco titles the advisory an authentication bypass, while CISA's catalog entry calls it an incorrect use of privileged APIs and tags it CWE-648. Neither has published exploitation detail beyond the fact that it is happening, and the vendor advisory carries whatever specifics exist.
Patch to 3.4 Patch 7 or 3.5 Patch 4, there is no workaround
Cisco lists the fixed builds as 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. The advisory says there are no workarounds that address the vulnerability, and offers infrastructure access control lists only as a temporary mitigation. On a product whose entire job is network access control, that is not a comfortable place to sit.
Check whether you were already hit
CISA's alert notes that Binding Operational Directive 26-04 sets expectations for when agencies must check whether threat actors compromised a system before the patch was applied, and both of the new entries are flagged for forensic triage. Patching closes the door. It does not tell you who came through it first. That is the same shape as the Cisco email gateway bug CISA flagged two days earlier, and the three-day ScreenConnect deadline before that.
The Acronis entry is quieter, not trivial
CVE-2026-87886 affects the Acronis Backup plugin for cPanel and WHM and the extension for Plesk. CISA describes it as an incorrect default permissions flaw that could allow for privilege escalation. Acronis rates it HIGH in its own advisory database, where it is titled a local privilege escalation due to insecure file permissions and dated 15 September. Acronis published two product updates the same day, Acronis Backup extension for Plesk 1.8.11 and Acronis Backup plugin for cPanel and WHM 1.9.3 HF3. Hosting control panels are shared machines by design, so a local escalation on one reaches a good deal further than the word local suggests.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.