we_are_coded.by CODE · The world, decoded
БГ
CISA

Three holes in one day on the exploited list: Cisco ISE, the Pixel modem and Acronis backup for cPanel

CISA · event date: 16 September 2026Security

CISA added three vulnerabilities already used in attacks on 16 September, with a patch deadline of 19 September. Closest to small business is the third - the backup plugin in hosting control panels.

In short
  • CVE-2026-76460 in Cisco ISE: authentication bypass with no account, score 10.0, active exploitation.
  • CVE-2026-58704 in the Pixel modem: fixed in security patch level 2026-09-05.
  • CVE-2026-87886 in Acronis Backup for cPanel & WHM, Plesk and DirectAdmin: local privilege escalation, already used in limited, targeted attacks against cPanel & WHM.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

CISA's catalogue of exploited vulnerabilities is the most boring document in security and the most useful. Only what is already being used in attacks gets in.

On Wednesday three went in at once, from three different worlds: network gear at large companies, a phone in your pocket and a hosting panel that carries small businesses' websites.

The facts: on 16 September 2026 CISA added three entries to its Known Exploited Vulnerabilities catalogue (KEV), with a deadline for federal agencies of 19 September. CVE-2026-76460 affects Cisco Identity Services Engine and ISE-PIC: an unauthenticated remote attacker can bypass authentication through an API and gain access to the device, regardless of configuration. Cisco scores it 10.0 on CVSS, writes that it is aware of active exploitation and that there is no workaround; as a mitigation it recommends access control lists that allow only required management traffic. The fixes are in 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. CVE-2026-58704 is in the cellular modem of Pixel phones - a logic error may allow a permission check to be bypassed; per the NVD description, an attacker on an adjacent network can escalate privileges with no user interaction. In the Pixel bulletin of 15 September Google writes that there are indications that the flaw may be under limited, targeted exploitation; the fix is in security patch level 2026-09-05. CVE-2026-87886 is in Acronis Backup - the plugin for cPanel & WHM and the extensions for Plesk and DirectAdmin on Linux: incorrect default permissions allow local privilege escalation. Acronis confirms exploitation in limited, targeted attacks against cPanel & WHM installations. The fixes are in build 1.9.3.1021 for cPanel & WHM, 1.8.11.638 for Plesk and 1.2.3.238 for DirectAdmin.

Which is for whom

Cisco ISE is for the network departments of large companies. If you have one, you already know. A score of 10 out of 10 and active exploitation leave no room for discussion, only for a maintenance window tonight.

Pixel is the easiest to fix and the easiest to underestimate. The update is ready for all supported models. Open the settings and check that the security patch level is 2026-09-05 or newer; it takes ten seconds.

The third is the quiet one. The Acronis plugin sits in the hosting control panel, where a website owner almost never looks. The vulnerability is local, meaning the attacker first needs some access to the server. On shared hosting, though, many accounts live on one machine, and one weak one is enough to start.

A local hole on a shared server rarely stays local.

If you run a server with cPanel, Plesk or DirectAdmin and use Acronis backups, check the plugin version today. If someone else manages your hosting, ask them with the vulnerability number in hand, and ask for a version, not a promise.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog, entries of 16.09.2026→Cisco Security Advisory - Cisco Identity Services Engine Authentication Bypass Vulnerability (cisco-sa-ISE-ABP-VNSW7Tn5), 16.09.2026→Android - Pixel Update Bulletin, September 2026, 15.09.2026→Acronis Advisory Database - SEC-10986→NVD - CVE-2026-58704
Original: https://wearecoded.com/en/articles/cisa-kev-cisco-ise-pixel-acronis-cpanel.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news