Government Advisory

CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup

CISA · 16 Sept 2026
Key Takeaway If your business uses Cisco Identity Services Engine or Acronis Backup, check for security updates now and apply them as a priority, since both flaws are already being exploited in the wild.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-76460, affects Cisco Identity Services Engine and involves incorrect use of privileged APIs. The second, CVE-2026-87886, affects Acronis Backup and stems from incorrect default permissions.

While CISA's directive requiring urgent remediation formally applies only to US federal agencies, the agency encourages all organisations, including small and medium businesses, to prioritise fixing vulnerabilities listed in the KEV catalogue. These flaws are attractive to attackers because they are proven to work and often provide significant control over affected systems once exploited.

Australian businesses using Cisco Identity Services Engine for network access control, or Acronis for backup and data protection, should check vendor advisories and apply available patches or mitigations promptly, since these are exactly the kinds of widely used products attackers target once exploitation details become public.

CISA known exploited vulnerabilities Cisco Acronis patch management

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.