Executive Summary

CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026: CVE-2026-76460 affecting Cisco Identity Services Engine's privileged API usage, and CVE-2026-87886 involving Acronis Backup's incorrect default permissions. Both vulnerabilities are actively exploited in the wild and pose significant risks to federal enterprises. The additions reinforce CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could grant total system control post-exploitation.

These KEV additions highlight the ongoing evolution of threat actor tactics targeting identity management systems and backup infrastructure, critical components in modern enterprise security architectures that attackers increasingly exploit for persistence and lateral movement.

Why This Matters Now

Federal agencies face immediate compliance deadlines under BOD 26-04 to remediate these actively exploited vulnerabilities, while the targeting of identity services and backup systems reflects attackers' focus on critical infrastructure that enables widespread network compromise and data exfiltration.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

CVE-2026-76460 is a Cisco Identity Services Engine vulnerability involving incorrect use of privileged APIs, while CVE-2026-87886 affects Acronis Backup with incorrect default permissions, both actively exploited in the wild.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this multi-stage attack by constraining lateral movement through east-west traffic controls and limiting unauthorized egress channels. The segmented architecture could have contained attacker reach across the compromised identity and backup infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust architecture may have limited the initial compromise scope by enforcing identity-aware access controls and reducing the attack surface available to exploit these API vulnerabilities.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have constrained privilege escalation by isolating workloads and limiting the scope of compromised credentials across different service boundaries within the infrastructure.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Traffic inspection and segmentation controls would likely have detected and blocked unauthorized lateral movement attempts between workloads, constraining the attacker's ability to traverse the internal network infrastructure.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive visibility across cloud environments may have detected the establishment of unauthorized command and control channels, limiting the attacker's ability to maintain persistent covert communication pathways.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have limited data exfiltration by blocking unauthorized outbound connections and constraining the attacker's ability to transmit sensitive data to external destinations.

Impact (Mitigations)

While service disruption may still occur within compromised segments, the overall organizational impact would likely be reduced through isolated failure domains and contained blast radius across the infrastructure.

Impact at a Glance

Affected Business Functions

  • Identity and Access Management
  • Network Security Operations
  • Data Backup and Recovery
  • Federal IT Infrastructure
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Federal agencies and organizations using affected Cisco ISE and Acronis Backup systems are at risk of unauthorized access to authentication systems and backup data repositories containing potentially sensitive government and enterprise information

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised identity services
  • Deploy Egress Security & Policy Enforcement to control and monitor outbound traffic from backup and identity systems
  • Enable Encrypted Traffic (HPE) for east-west communications to protect data in transit between workloads
  • Establish Multicloud Visibility & Control to detect anomalous interactions and suspicious automation from compromised systems
  • Deploy Inline IPS (Suricata) to identify and block exploit traffic targeting known CVE vulnerabilities like those in the KEV catalog

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image