Executive Summary
CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026: CVE-2026-76460 affecting Cisco Identity Services Engine's privileged API usage, and CVE-2026-87886 involving Acronis Backup's incorrect default permissions. Both vulnerabilities are actively exploited in the wild and pose significant risks to federal enterprises. The additions reinforce CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could grant total system control post-exploitation.
These KEV additions highlight the ongoing evolution of threat actor tactics targeting identity management systems and backup infrastructure, critical components in modern enterprise security architectures that attackers increasingly exploit for persistence and lateral movement.
Why This Matters Now
Federal agencies face immediate compliance deadlines under BOD 26-04 to remediate these actively exploited vulnerabilities, while the targeting of identity services and backup systems reflects attackers' focus on critical infrastructure that enables widespread network compromise and data exfiltration.
Attack Path Analysis
Attackers exploited CVE-2026-76460 (Cisco ISE API vulnerability) and CVE-2026-87886 (Acronis Backup permissions) to gain initial access through privileged API misuse and default permission abuse. They escalated privileges within the compromised systems, moved laterally through unencrypted east-west traffic, established command and control through unmonitored egress channels, exfiltrated data via unauthorized destinations, and caused operational impact through service disruption and data compromise.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2026-76460 Cisco ISE privileged API vulnerability and CVE-2026-87886 Acronis Backup default permissions vulnerability to gain unauthorized access
Related CVEs
CVE-2026-76460
CVSS 10Cisco Identity Services Engine contains an incorrect use of privileged APIs vulnerability that allows authenticated attackers to perform unauthorized privileged operations.
Affected Products:
Cisco Identity Services Engine – < 3.2.1
Exploit Status:
exploited in the wildCVE-2026-87886
CVSS 7.5Acronis Backup contains an incorrect default permissions vulnerability that allows attackers to gain unauthorized access to backup data and systems.
Affected Products:
Acronis Backup – < 12.5.1.16341
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Valid Accounts
Abuse Elevation Control Mechanism
Exploitation for Defense Evasion
Hijack Execution Flow
Supply Chain Compromise
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Process
Control ID: 6.3.1
NYDFS 23 NYCRR 500 – Risk Assessment and System Vulnerability Management
Control ID: 500.09
CISA Zero Trust Maturity Model 2.0 – Asset Management and Vulnerability Assessment
Control ID: 4.2
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory KEV remediation under BOD 26-04, requiring rapid patching of Cisco ISE and Acronis vulnerabilities on publicly exposed assets.
Information Technology/IT
IT services using Cisco Identity Services Engine and Acronis Backup face active exploitation risks requiring immediate vulnerability management and Zero Trust segmentation implementation.
Financial Services
Banking systems using affected identity management and backup solutions must prioritize PCI compliance requirements and implement egress security controls against data exfiltration.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance risks from identity service vulnerabilities, requiring enhanced access controls and encrypted traffic monitoring for patient data protection.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskhttps://www.cisa.gov/directivesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this multi-stage attack by constraining lateral movement through east-west traffic controls and limiting unauthorized egress channels. The segmented architecture could have contained attacker reach across the compromised identity and backup infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust architecture may have limited the initial compromise scope by enforcing identity-aware access controls and reducing the attack surface available to exploit these API vulnerabilities.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained privilege escalation by isolating workloads and limiting the scope of compromised credentials across different service boundaries within the infrastructure.
Control: East-West Traffic Security
Mitigation: Traffic inspection and segmentation controls would likely have detected and blocked unauthorized lateral movement attempts between workloads, constraining the attacker's ability to traverse the internal network infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Comprehensive visibility across cloud environments may have detected the establishment of unauthorized command and control channels, limiting the attacker's ability to maintain persistent covert communication pathways.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have limited data exfiltration by blocking unauthorized outbound connections and constraining the attacker's ability to transmit sensitive data to external destinations.
While service disruption may still occur within compromised segments, the overall organizational impact would likely be reduced through isolated failure domains and contained blast radius across the infrastructure.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- Network Security Operations
- Data Backup and Recovery
- Federal IT Infrastructure
Estimated downtime: 7 days
Estimated loss: N/A
Federal agencies and organizations using affected Cisco ISE and Acronis Backup systems are at risk of unauthorized access to authentication systems and backup data repositories containing potentially sensitive government and enterprise information
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised identity services
- • Deploy Egress Security & Policy Enforcement to control and monitor outbound traffic from backup and identity systems
- • Enable Encrypted Traffic (HPE) for east-west communications to protect data in transit between workloads
- • Establish Multicloud Visibility & Control to detect anomalous interactions and suspicious automation from compromised systems
- • Deploy Inline IPS (Suricata) to identify and block exploit traffic targeting known CVE vulnerabilities like those in the KEV catalog



