CISA adds three exploited vulnerabilities on September 16
The most consequential item today is CVE-2026-76460, a CVSS 10 flaw in Cisco Identity Services Engine tied to incorrect use of privileged APIs. CISA added it to the Known Exploited Vulnerabilities catalog on September 16 alongside two others. ISE sits at the center of network access control, so a privileged-API weakness there is exactly the kind of thing you patch now rather than schedule for later.
Joining it are CVE-2026-58704, a CVSS 8.8 improper authorization flaw in Google Pixel, and CVE-2026-87886, an incorrect default permissions bug in Acronis Backup. All three are KEV-listed, which means confirmed exploitation, not theory.
- CVE-2026-76460 - Cisco Identity Services Engine, CVSS 10, KEV added 2026-09-16
- CVE-2026-58704 - Google Pixel, CVSS 8.8, KEV added 2026-09-16
- CVE-2026-87886 - Acronis Backup, KEV added 2026-09-16
Pixel modem zero-day and Acronis backup plugin under active attack
SecurityWeek and BleepingComputer both report the Pixel issue as an actively exploited Android zero-day used in targeted attacks, and Google has shipped fixes for Pixel devices. If you manage Pixel hardware through Intune, push the update and confirm compliance rather than trusting the enrollment count.
On the Acronis side, Help Net Security and BleepingComputer describe CVE-2026-87886 as an exploited flaw in the Acronis cPanel backup plugin, with attacks already observed in the wild. Backup tooling is a favorite target because it holds broad access and is often left off the standard patch cadence.
Exploitation picture: what is hot right now
Beyond today's additions, the KEV movers worth your attention carry ransomware links, which raises the urgency. CVE-2026-15409 in SonicWall SMA1000 (CVSS 10, EPSS 0.85), CVE-2026-59310 in Broadcom VMware vCenter (CVSS 9.8), and CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, EPSS 0.99) are all KEV-listed and ransomware-associated. CVE-2026-41940 has the highest exploitation probability of the group.
BleepingComputer also reports that the critical ConnectWise ScreenConnect flaw, CVE-2026-84869 (CVSS 9.9), is now actively exploited, with CISA warning about it. GitLab's CVE-2026-85706 path traversal, covered by Dark Reading and Rapid7 as a maximum-severity supply-chain risk, remains KEV-listed and exploited in the wild.
Windows patch reliability caveats
If you are staging Microsoft updates, note the operational fallout. BleepingComputer reports Windows 11 KB5124008 breaks domain trust for some users, and Qualys flags both KB5124008 and KB5124012 in a piece on patch reliability. Dark Reading adds that Microsoft issued emergency fixes after this month's large Patch Tuesday. Test domain-joined systems before broad deployment.
The KEV-flagged cumulative updates KB5046616 and KB5046698 for Windows Server 2022 each address 37 CVEs, so you cannot simply skip them. Balance the trust-break risk against the exploited-vulnerability count.
Do this first
Prioritize by confirmed exploitation and ransomware linkage, then work down.
- Patch Cisco Identity Services Engine for CVE-2026-76460 (CVSS 10, KEV) as your top action.
- Update Pixel devices for CVE-2026-58704 and confirm Intune compliance.
- Patch Acronis Backup for CVE-2026-87886; treat backup infrastructure as production.
- Address ransomware-linked KEV items: SonicWall CVE-2026-15409, VMware vCenter CVE-2026-59310, cPanel CVE-2026-41940, and ScreenConnect CVE-2026-84869.
- Test KB5124008 and KB5124012 for domain trust issues before rolling Windows updates broadly.
- Use the Senserva free Microsoft Patch Tracker to rank open patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft CVE tracker to follow KEV additions daily.
Sources
- CISA Cybersecurity Advisories: CISA Adds Two Known Exploited Vulnerabilities to Catalog (2026-09-16)
- CISA Cybersecurity Advisories: CISA Adds One Known Exploited Vulnerability to Catalog (2026-09-16)
- SecurityWeek: Pixel Modem Zero-Day Exploited in Targeted Attacks (2026-09-16)
- Help Net Security: Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886) (2026-09-16)
- BleepingComputer: Google fixes actively exploited Android zero-day on Pixel devices (2026-09-16)
- BleepingComputer: Critical ScreenConnect flaw now actively exploited in attacks (2026-09-16)
- BleepingComputer: Windows 11 KB5124008 update breaks domain trust for some users (2026-09-16)
- BleepingComputer: Acronis warns of actively exploited flaw in its cPanel backup plugin (2026-09-15)
- Qualys: Before You Patch. Why Patch Reliability Matters for Confident Deployment (2026-09-15)
- Dark Reading: Maximum Severity GitLab Flaw Puts Supply Chains at Risk (2026-09-14)
- Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (2026-09-14)
- Dark Reading: Microsoft Issues Emergency Fixes After Massive Patch Tuesday (2026-09-15)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-17.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.