On September 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) took action to address two significant vulnerabilities being actively exploited in the wild by adding them to its Known Exploited Vulnerabilities (KEV) catalog. The additions are CVE-2026-76460, a CVSS 10.0 authentication bypass in Cisco Identity Services Engine (ISE), and CVE-2026-87886, an incorrect default permissions vulnerability in Acronis Backup. This action triggers Binding Operational Directive (BOD) 26-04, which mandates that Federal Civilian Executive Branch (FCEB) agencies must remediate these flaws within a specified timeframe to protect federal networks from active threats.
The KEV catalog is a cornerstone of CISA's strategy to focus defensive efforts on vulnerabilities that pose the most immediate risk. A vulnerability is added to the catalog only when there is reliable evidence of active exploitation. Under BOD 26-04, once a flaw is added, FCEB agencies are given a specific deadline to apply patches or mitigations.
For the newly added vulnerabilities:
While the directive is only mandatory for FCEB agencies, CISA strongly urges all public and private sector organizations to review the KEV catalog and prioritize the remediation of these vulnerabilities to reduce their exposure to active cyber threats.
The primary group mandated to act are U.S. Federal Civilian Executive Branch (FCEB) agencies. However, the inclusion of these vulnerabilities serves as a strong advisory for all organizations, including state and local governments, critical infrastructure operators, and private companies globally. Any organization using the affected Cisco or Acronis products is at risk and should prioritize remediation.
For FCEB agencies, compliance with BOD 26-04 is not optional. They must take the following actions:
The directive also requires agencies to check for signs of system compromise before applying patches and to take appropriate incident response measures if a breach is suspected.
These tight deadlines reflect the high risk associated with actively exploited vulnerabilities, especially for a flaw as critical as the Cisco ISE authentication bypass.
By maintaining the KEV catalog, CISA helps organizations move beyond a purely CVSS-based vulnerability management model to a threat-informed approach. Prioritizing KEVs allows security teams to focus limited resources on the flaws that are actively being used by adversaries, significantly reducing the organization's attack surface and the likelihood of a successful breach. For federal agencies, adherence to the directive is a key metric of their cybersecurity posture and resilience.
All organizations, not just federal agencies, should incorporate the KEV catalog into their vulnerability management programs.
The primary mitigation required by CISA's directive is to apply vendor patches for the identified vulnerabilities.
Mapped D3FEND Techniques:
Organizations must adopt a threat-informed approach to patch management by integrating the CISA KEV catalog. When a vulnerability like CVE-2026-76460 or CVE-2026-87886 is added, it should trigger an emergency patching process. This process should supersede standard, scheduled patch cycles. Security and IT teams must have a clear, documented procedure to quickly identify affected assets using asset inventory and vulnerability scanning tools, test patches where feasible, and deploy them to production systems within the CISA-mandated timeframe (or a similarly aggressive internal SLA). This requires robust coordination, automated deployment tools (e.g., SCCM, Ansible), and clear communication channels to ensure rapid risk reduction across the enterprise.
CISA adds CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities (KEV) catalog.
Remediation deadline for CVE-2026-76460 for FCEB agencies.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.