CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
About this summary. This is a short, independently written summary of an article first published by CISA. Cyber Security News did not report or verify the underlying story. Read the original: https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
Source attribution: headline and facts are from CISA (cisa.gov). Summary method: excerpt of the source description. See our source attribution policy.





