CISA added three vulnerabilities already used in attacks on 16 September, with a patch deadline of 19 September. Closest to small business is the third - the backup plugin in hosting control panels.
- CVE-2026-76460 in Cisco ISE: authentication bypass with no account, score 10.0, active exploitation.
- CVE-2026-58704 in the Pixel modem: fixed in security patch level 2026-09-05.
- CVE-2026-87886 in Acronis Backup for cPanel & WHM, Plesk and DirectAdmin: local privilege escalation, already used in limited, targeted attacks against cPanel & WHM.
CISA's catalogue of exploited vulnerabilities is the most boring document in security and the most useful. Only what is already being used in attacks gets in.
On Wednesday three went in at once, from three different worlds: network gear at large companies, a phone in your pocket and a hosting panel that carries small businesses' websites.
Which is for whom
Cisco ISE is for the network departments of large companies. If you have one, you already know. A score of 10 out of 10 and active exploitation leave no room for discussion, only for a maintenance window tonight.
Pixel is the easiest to fix and the easiest to underestimate. The update is ready for all supported models. Open the settings and check that the security patch level is 2026-09-05 or newer; it takes ten seconds.
The third is the quiet one. The Acronis plugin sits in the hosting control panel, where a website owner almost never looks. The vulnerability is local, meaning the attacker first needs some access to the server. On shared hosting, though, many accounts live on one machine, and one weak one is enough to start.
If you run a server with cPanel, Plesk or DirectAdmin and use Acronis backups, check the plugin version today. If someone else manages your hosting, ask them with the vulnerability number in hand, and ask for a version, not a promise.