CISA Adds Three New Vulnerabilities to Its Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog.
The vulnerabilities, which affect Acronis Backup, Cisco Identity Services Engine, and Google Pixel devices, were identified as being actively exploited in the wild.
Cisco's Identity Services Engine vulnerability, CVE-2026-76460, is an authentication bypass flaw that can allow an unauthenticated remote attacker to gain unauthorized access to the affected system. The company has recommended that customers upgrade to a fixed software release to remediate this vulnerability.
Acronis Backup's local privilege escalation vulnerability, CVE-2026-87886, allows a local attacker with limited privileges to manipulate files used by the backup service and potentially execute code with elevated, root-level privileges.