CISA KEV Catalog Updated with Cisco and Acronis Vulnerabilities

CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog

HIGH
September 17, 2026
3m read
VulnerabilityRegulatoryPatch Management

Related Entities

Organizations

Products & Tech

Cisco Identity Services EngineAcronis Backup

CVE Identifiers

CVE-2026-76460
CRITICAL
CVSS:10

Full Report

Executive Summary

On September 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) took action to address two significant vulnerabilities being actively exploited in the wild by adding them to its Known Exploited Vulnerabilities (KEV) catalog. The additions are CVE-2026-76460, a CVSS 10.0 authentication bypass in Cisco Identity Services Engine (ISE), and CVE-2026-87886, an incorrect default permissions vulnerability in Acronis Backup. This action triggers Binding Operational Directive (BOD) 26-04, which mandates that Federal Civilian Executive Branch (FCEB) agencies must remediate these flaws within a specified timeframe to protect federal networks from active threats.


Regulatory Details

The KEV catalog is a cornerstone of CISA's strategy to focus defensive efforts on vulnerabilities that pose the most immediate risk. A vulnerability is added to the catalog only when there is reliable evidence of active exploitation. Under BOD 26-04, once a flaw is added, FCEB agencies are given a specific deadline to apply patches or mitigations.

For the newly added vulnerabilities:

  • CVE-2026-76460 (Cisco ISE): A critical flaw allowing a complete authentication bypass. Due to its severity, FCEB agencies are required to apply patches by September 19, 2026.
  • CVE-2026-87886 (Acronis Backup): An incorrect default permissions flaw. The specific remediation deadline for this vulnerability was also set by CISA to drive prompt action.

While the directive is only mandatory for FCEB agencies, CISA strongly urges all public and private sector organizations to review the KEV catalog and prioritize the remediation of these vulnerabilities to reduce their exposure to active cyber threats.

Affected Organizations

The primary group mandated to act are U.S. Federal Civilian Executive Branch (FCEB) agencies. However, the inclusion of these vulnerabilities serves as a strong advisory for all organizations, including state and local governments, critical infrastructure operators, and private companies globally. Any organization using the affected Cisco or Acronis products is at risk and should prioritize remediation.

Compliance Requirements

For FCEB agencies, compliance with BOD 26-04 is not optional. They must take the following actions:

  1. Identify: Identify all affected assets on their networks.
  2. Remediate: Apply the vendor-supplied patches by the CISA-mandated deadline.
  3. Report: Report the status of remediation back to CISA through established channels.

The directive also requires agencies to check for signs of system compromise before applying patches and to take appropriate incident response measures if a breach is suspected.

Implementation Timeline

  • CVE-2026-76460: Remediation deadline is September 19, 2026.
  • CVE-2026-87886: Remediation deadline is October 7, 2026.

These tight deadlines reflect the high risk associated with actively exploited vulnerabilities, especially for a flaw as critical as the Cisco ISE authentication bypass.

Impact Assessment

By maintaining the KEV catalog, CISA helps organizations move beyond a purely CVSS-based vulnerability management model to a threat-informed approach. Prioritizing KEVs allows security teams to focus limited resources on the flaws that are actively being used by adversaries, significantly reducing the organization's attack surface and the likelihood of a successful breach. For federal agencies, adherence to the directive is a key metric of their cybersecurity posture and resilience.

Compliance Guidance

All organizations, not just federal agencies, should incorporate the KEV catalog into their vulnerability management programs.

  1. Subscribe to Updates: Regularly monitor the KEV catalog for new additions. CISA provides automated feeds for this purpose.
  2. Prioritize Patching: When a vulnerability present in your environment is added to the KEV, it should be elevated to the highest priority for patching, overriding standard schedules.
  3. Enhance Monitoring: For systems that cannot be patched immediately, implement enhanced monitoring and compensating controls to detect and block exploitation attempts. This aligns with D3FEND's Network Traffic Analysis (D3-NTA).
  4. Assume Breach: When patching a KEV, especially on an internet-facing system, it is prudent to hunt for signs of compromise, as the system may have been breached before the patch was applied.

Timeline of Events

1
September 16, 2026
CISA adds CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities (KEV) catalog.
2
September 17, 2026
This article was published
3
September 19, 2026
Remediation deadline for CVE-2026-76460 for FCEB agencies.

MITRE ATT&CK Mitigations

The primary mitigation required by CISA's directive is to apply vendor patches for the identified vulnerabilities.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

Organizations must adopt a threat-informed approach to patch management by integrating the CISA KEV catalog. When a vulnerability like CVE-2026-76460 or CVE-2026-87886 is added, it should trigger an emergency patching process. This process should supersede standard, scheduled patch cycles. Security and IT teams must have a clear, documented procedure to quickly identify affected assets using asset inventory and vulnerability scanning tools, test patches where feasible, and deploy them to production systems within the CISA-mandated timeframe (or a similarly aggressive internal SLA). This requires robust coordination, automated deployment tools (e.g., SCCM, Ansible), and clear communication channels to ensure rapid risk reduction across the enterprise.

Timeline of Events

1
September 16, 2026

CISA adds CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities (KEV) catalog.

2
September 19, 2026

Remediation deadline for CVE-2026-76460 for FCEB agencies.

Sources & References

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
The Hacker News (thehackernews.com) September 17, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CISAKEVBOD 26-04vulnerability managementpatchingfederal government

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.