The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities in Cisco ISE, Acronis Backup, and Google Pixel devices to its Known Exploited Vulnerabilities (KEV) catalog, mandating urgent patching for federal agencies and signaling immediate risk for all organizations.
The most severe flaw is CVE-2026-76460, an authentication bypass in an API for Cisco Identity Services Engine (ISE). CISA confirms this vulnerability is under active exploitation, with the potential for a remote attacker to gain full administrative control of the platform often used for enterprise network access and policy enforcement.
Inclusion in the KEV catalog triggers a non-negotiable remediation timeline for U.S. federal agencies under Binding Operational Directive 22-01. For IT teams worldwide, this directive establishes a clear priority: KEV-listed vulnerabilities represent confirmed, ongoing threats that supersede routine maintenance cycles.
The directive's action requirement is clear. A compromised Cisco ISE could allow attackers to manipulate network segmentation, intercept traffic, and move laterally. A breach of Acronis Backup systems could undermine data integrity and enable ransomware, while vulnerabilities in Google Pixel endpoints directly compromise device security.
Administrators are directed to the full CISA KEV catalog entry for complete technical details and specific CVE identifiers for the Acronis and Google vulnerabilities. Security teams must immediately audit their environments for these systems and apply vendor-supplied patches without delay to mitigate these confirmed active threats.
美國網絡安全和基礎設施安全局(CISA)已將 Cisco ISE、Acronis Backup 及 Google Pixel 設備中的關鍵漏洞加入其已知被利用漏洞(KEV)目錄,勒令聯邦機構緊急修補,並向所有組織發出即時風險警示。
最嚴重的漏洞為 CVE-2026-76460,涉及 Cisco Identity Services Engine(ISE)一個 API 中的認證繞過。CISA 確認該漏洞正遭積極利用,遠端攻擊者或可藉此取得這個常用於企業網絡存取及策略執行平台的完整管理控制權。
根據《具有約束力的行動指令 22-01》,列入 KEV 目錄觸發美國聯邦機構無可協商的補救時限。對於全球的 IT 團隊而言,該指令確立了明確的優先級:KEV 列出的漏洞代表已確認的持續威脅,優先級高於日常維護週期。
指令的行動要求十分明確。一個被入侵的 Cisco ISE 可能讓攻擊者操控網絡分區、截取流量並進行橫向移動。Acronis Backup 系統遭破壞可能危害數據完整性並助長勒索軟件,而 Google Pixel 端點的漏洞則直接危及設備安全。
管理員應查閱完整的 CISA KEV 目錄條目,以獲取有關 Acronis 及 Google 漏洞的完整技術細節及具體 CVE 編號。安全團隊必須立即審計其環境中的這些系統,並毫不延遲地套用供應商提供的補丁,以緩解這些確認的活躍威脅。
