CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-76460 and CVE-2026-87886, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities, affecting Cisco Identity Services Engine and Acronis Backup respectively, pose significant risks and are frequent attack vectors. CISA urges all organizations, particularly federal agencies, to prioritize remediation of these KEV cataloged vulnerabilities.

IFF Assessment

FOE

The article details new vulnerabilities added to CISA's KEV catalog, indicating active exploitation and posing significant risks to organizations, which is bad news for defenders.

Severity

CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of the newly added CVEs to CISA's KEV catalog as they represent actively exploited threats. Prioritizing patching and mitigation for these vulnerabilities, especially on internet-facing assets, is crucial to prevent compromise. This reinforces the importance of a robust vulnerability management program that actively tracks and addresses known exploited vulnerabilities.

Read Full Story →