CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-76460, affects Cisco Identity Services Engine and involves incorrect use of privileged APIs. The second, CVE-2026-87886, affects Acronis Backup and stems from incorrect default permissions.
While CISA's directive requiring urgent remediation formally applies only to US federal agencies, the agency encourages all organisations, including small and medium businesses, to prioritise fixing vulnerabilities listed in the KEV catalogue. These flaws are attractive to attackers because they are proven to work and often provide significant control over affected systems once exploited.
Australian businesses using Cisco Identity Services Engine for network access control, or Acronis for backup and data protection, should check vendor advisories and apply available patches or mitigations promptly, since these are exactly the kinds of widely used products attackers target once exploitation details become public.