Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, government] Β· confidence: high Β· severity: critical Β· affected_sectors: [government] Β· au_impact: true

After a four-day pause, CISA's Known Exploited Vulnerabilities catalogue advanced to version 2026.09.16 carrying three additions dated 16 September, the first of which the agency announced formally: CVE-2026-58704, a Google Pixel improper-authorisation vulnerability. Google's own advisory, published the same day, is more specific β€” the flaw sits in the Pixel Cellular Modem, is described in the NVD as a possible permission bypass arising from a logic error, carries a CVSS score of 8.0, and permits remote (proximal/adjacent) privilege escalation without user interaction; Google states it has found indications that the bug "may be under limited, targeted exploitation" but has not described the attacks or named an actor, and the same release addressed 109 other flaws. The catalogue also carries new 16 September entries for CVE-2026-76460, a Cisco Identity Services Engine privileged-API misuse vulnerability, and CVE-2026-87886, an Acronis Backup flaw caused by insecure file permissions. The Acronis entry has first-party corroboration: the company warned that a high-severity local privilege-escalation flaw in its Backup plugin for cPanel and Web Host Manager on Linux (before build 1.9.3.1021, fixed in 1.9.3 HF3) and its Plesk extension (before 1.8.11.638) has been exploited in the wild, telling customers the update "should be installed immediately by all users" and that exploitation had been detected in limited, targeted attacks. Across the three, the pattern is the one this digest has tracked for two weeks β€” device, identity and backup infrastructure, all n-day-class issues rather than zero-days, and all with the remediation clock set by the catalogue rather than by vendor advisories. The compliance consequence remains Binding Operational Directive 26-04, which requires federal civilian agencies to prioritise KEV-listed flaws on publicly exposed assets and to check whether a system was compromised before the patch was applied; CISA encourages organisations outside the federal enterprise to adopt the same risk-based prioritisation.

Attribute Detail
Sector Government
Date 2026-09-17
Source CISA
Reliability Tier 1
CVEs CVE-2026-58704, CVE-2026-76460, CVE-2026-87886