CISA KEV Adds Cisco ISE and Acronis Backup: What Central Valley IT Teams Should Do Now — Datapath managed IT, cybersecurity, and compliance
Back to Blog
GENERAL Insights Published September 23, 2026 Updated September 23, 2026 10 min read

CISA KEV Adds Cisco ISE and Acronis Backup: What Central Valley IT Teams Should Do Now

CISA added actively exploited Cisco ISE and Acronis Backup vulnerabilities to the KEV Catalog. Here is the practical response plan for Modesto and Central Va…

Dan J Sturdivant, Vice President at Datapath

By

Dan J Sturdivant

Vice President

Central Valleycompliancecybersecurity

Quick summary

  • Find the systems.
  • What did CISA add to the KEV Catalog on September 16, 2026?
  • Why are identity and backup vulnerabilities more urgent than normal endpoint bugs?

What did CISA add to the KEV Catalog on September 16, 2026?

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog on September 16, 2026: CVE-2026-76460 in Cisco Identity Services Engine and CVE-2026-87886 in Acronis Backup. For Central Valley IT leaders, the signal is direct: identity infrastructure and backup infrastructure both need emergency verification, not ordinary patch-cycle handling.1

This matters because both product categories sit near the center of recovery operations. Cisco Identity Services Engine, commonly called Cisco ISE, often governs network access, device authentication, segmentation, and policy enforcement. Acronis Backup integrations sit near the systems organizations depend on when ransomware, data loss, or infrastructure failure forces a restore.

When CISA adds a vulnerability to the KEV Catalog, it is not saying “this could theoretically be exploited.” It is saying there is evidence of active exploitation. CISA also states that organizations should use the KEV Catalog as an input to vulnerability management prioritization, not as background reading.2

For a healthcare clinic in Modesto, a school district in Stanislaus County, a manufacturer in Fresno, or a financial office with regulated data, the practical question is not “Do we have a CVE tracker?” The practical question is: can we prove whether exposed identity and backup systems are affected, remediated, and clean?

Why are identity and backup vulnerabilities more urgent than normal endpoint bugs?

Identity and backup vulnerabilities are more urgent because they affect the systems defenders use to control access and recover after failure. If attackers compromise identity policy systems, they may weaken segmentation or gain management access. If they compromise backup systems, they may damage restore confidence exactly when the business needs it most.

CISA’s September 16 alert named CVE-2026-76460 as a Cisco Identity Services Engine “Incorrect Use of Privileged APIs” vulnerability and CVE-2026-87886 as an Acronis Backup “Incorrect Default Permissions” vulnerability.1 The KEV Catalog further states that forensic triage is required for both entries under CISA’s BOD-26-04 framework, with a due date of September 19, 2026 for covered federal civilian agencies.2

Even though Binding Operational Directives apply to federal civilian agencies, the operational lesson applies broadly: exploited vulnerabilities in externally reachable or high-control infrastructure deserve faster handling than routine workstation patching. A flat “monthly patch Tuesday” approach is too slow for systems that can grant access, control network policy, or influence recovery.

The Cisco entry is especially concerning because NIST’s National Vulnerability Database describes CVE-2026-76460 as an API vulnerability that could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to the affected device through the web-based management interface. Cisco’s CNA score listed in NVD is 10.0 Critical.3

The Acronis entry has a different shape. NVD describes CVE-2026-87886 as local privilege escalation due to insecure file permissions affecting Acronis Backup plugin and extension builds for Linux hosting control panels, including cPanel & WHM, Plesk, and DirectAdmin integrations. The CNA score listed in NVD is 7.8 High.4 That is not the same as unauthenticated remote access, but local escalation inside backup-adjacent infrastructure is still a serious recovery-risk issue.

What should Modesto and Central Valley IT teams check first?

Start with asset exposure, affected versions, and forensic triage. Do not begin with a generic patch report. For Cisco ISE, confirm whether any ISE or ISE-PIC management interface is internet-accessible, reachable from broad internal networks, or running an affected release. For Acronis, confirm whether Linux backup integrations for cPanel, WHM, Plesk, or DirectAdmin are present.

A practical first-hour checklist should include:

  1. Find the systems. Identify Cisco ISE, Cisco ISE-PIC, and Acronis Backup plugin or extension deployments. Do not rely only on the CMDB if network scans, RMM inventory, firewall objects, or DNS records show different evidence.
  2. Check exposure. Determine whether web management interfaces are reachable from the public internet, vendor VPNs, unmanaged admin workstations, or broad internal VLANs.
  3. Verify versions and builds. Compare deployed versions against vendor guidance and the NVD/CISA references. For Acronis, NVD lists affected builds before Acronis Backup plugin for cPanel & WHM build 1.9.3.1021, Acronis Backup extension for Plesk build 1.8.11.638, and Acronis Backup plugin for DirectAdmin build 1.2.4.238.4
  4. Apply mitigations or upgrades. CISA’s KEV action language is explicit: apply mitigations in accordance with vendor instructions or discontinue use if mitigations are unavailable.2
  5. Perform forensic triage. Because the KEV Catalog marks forensic triage as required for these entries under BOD-26-04, organizations should review logs, authentication events, administrative actions, configuration changes, and backup-job integrity instead of assuming a patch closes the incident window.2
  6. Document evidence. Preserve screenshots, command output, ticket notes, change approvals, version checks, firewall exposure records, and triage results.

That last point is where many lean IT teams fail. They patch, but they cannot later prove what was vulnerable, what was exposed, who approved the change, what was inspected, or whether the environment showed signs of prior compromise.

For regulated organizations, undocumented remediation is weak remediation.

How should healthcare, K-12, and local government teams prioritize this?

Healthcare, K-12, and local government teams should prioritize these systems according to business blast radius, not just CVSS. Identity control planes, network access systems, and backup tools affect downtime, incident response, compliance evidence, and restoration confidence. The systems that support recovery should be treated as Tier 0 or near-Tier 0 infrastructure.

A Central Valley clinic may not have Cisco ISE. A school district may not use Acronis hosting integrations. A city department may run a different NAC or backup platform entirely. The larger lesson still applies: when CISA confirms active exploitation in tools adjacent to identity and recovery, the correct response is to check your equivalents.

For healthcare organizations, that means verifying whether network access controls protect EHR workstations, imaging systems, VoIP phones, wireless medical devices, and administrative endpoints. It also means confirming backups can be restored without relying on a compromised console or privileged account.

For K-12 school districts, it means checking whether identity, wireless authentication, endpoint segmentation, and backup administration are split across too many unmanaged consoles. If the same small team manages student devices, staff identity, firewalls, wireless, and backups, a single management-plane compromise can create disproportionate damage.

For local government and public-sector teams, it means making incident evidence board-ready. City managers and department heads do not need raw CVE chatter. They need a clear answer: affected or not affected, exposed or not exposed, remediated or not remediated, evidence retained or not retained.

What evidence should executives ask for?

Executives should ask for a short remediation packet that proves discovery, exposure review, version status, mitigation, and triage. A verbal “we patched it” is not enough for exploited vulnerabilities. The packet should be simple enough for leadership to understand and detailed enough for audit, insurance, or incident-response review.

A useful evidence packet includes:

  • System inventory showing whether Cisco ISE, Cisco ISE-PIC, or affected Acronis Backup integrations exist.
  • Version and build evidence collected after remediation.
  • Firewall and remote-access evidence showing whether management interfaces were exposed.
  • Vendor mitigation or upgrade references used by the IT team.
  • Log-review summary for suspicious administrative activity, authentication bypass indicators, privilege escalation signs, or unexpected backup-system changes.
  • Backup validation notes, especially if Acronis or another backup-control system was in scope.
  • Change tickets with dates, approvers, implementers, and rollback notes.
  • Any compensating controls applied, such as management-interface restrictions, MFA enforcement, jump-host requirements, or temporary service shutdown.

This does not need to become a 60-page report. In fact, a concise two-to-five-page remediation record is usually more useful than a bloated document nobody reads. The goal is to preserve decision-quality evidence before logs rotate, staff memory fades, or an auditor asks for proof three months later.

How does this affect backup and disaster recovery planning?

This KEV update reinforces a hard rule: backup software is part of the security perimeter. If backup agents, backup consoles, hosting-control-panel integrations, or restore credentials are weak, the organization’s ransomware recovery plan is weaker than it looks on paper.

A disaster recovery plan should answer three questions after a backup-adjacent vulnerability:

  1. Were backup-control systems affected?
  2. Were backup jobs, retention settings, repositories, or restore points changed?
  3. Can the organization prove a clean restore from a known-good point?

If the answer to any of those is “unknown,” the organization does not have recovery confidence. It has recovery hope.

Datapath’s disaster recovery services are built around the practical side of that problem: recovery plans must be tested, documented, and tied to business operations. A backup product alone does not create resilience. Resilience comes from knowing which systems matter, how quickly they must return, who can authorize recovery, and what evidence proves the restore path works.

For organizations that do not have mature internal security staffing, this is also where managed IT services in Modesto and co-managed support become operationally useful. The real value is not “someone installs patches.” The value is maintaining the process discipline to identify exposure, prioritize exploited vulnerabilities, verify remediation, document evidence, and keep recovery systems trustworthy.

What should the remediation timeline look like?

For actively exploited vulnerabilities in identity or backup infrastructure, the timeline should be measured in hours and days, not weeks. Triage should start the same business day the exposure is identified. If a system is internet-facing and affected, restrict access immediately while remediation is prepared.

A reasonable response timeline:

  • Same day: identify assets, confirm exposure, restrict public or broad management access, open an incident/change record, and assign an owner.
  • Within 24 hours: validate versions, apply vendor mitigation or upgrade, collect evidence, and review logs for suspicious activity.
  • Within 48 to 72 hours: validate that backups and identity policies still behave as expected, close obvious exposure gaps, and brief leadership.
  • Within one week: convert the response into a reusable playbook for future KEV items affecting management-plane systems.

The exact timeline depends on business operations, maintenance windows, and system criticality. But waiting for a routine monthly cycle is the wrong default when CISA has already confirmed active exploitation.

What should organizations do if they do not use Cisco ISE or Acronis?

If you do not use Cisco ISE or affected Acronis Backup integrations, use this event as a control-plane review trigger. Identify your network access control platform, identity administration consoles, backup products, remote management tools, RMM platform, hypervisor management layer, and cloud admin portals. Then decide whether each one has proper access controls, patch ownership, logging, and recovery documentation.

The best organizations use KEV updates to improve the system, not just close one ticket. They ask:

  • Which tools can change authentication, segmentation, or administrative access?
  • Which tools can delete, encrypt, age out, or restore backups?
  • Which consoles are reachable from the internet or vendor remote access?
  • Which systems have MFA, restricted management networks, and named-user admin accounts?
  • Which logs would prove whether abuse occurred?
  • Which recovery steps depend on the very tool that might be compromised?

That review is more valuable than a one-time CVE scramble.

When should an outside provider be involved?

Bring in outside help when your team cannot quickly prove exposure, patch status, forensic triage, or restore confidence. This is especially true for lean IT teams responsible for regulated environments, multi-site operations, healthcare systems, school networks, or local-government services.

Datapath’s cybersecurity risk assessment services can help organizations translate advisories like this into an actionable risk register, remediation evidence, and prioritized control improvements. The goal is not alarmism. The goal is accountable execution: know what you run, know what is exposed, fix what matters first, and preserve evidence.

Bottom line for Central Valley IT leaders

CISA’s September 16 KEV additions are a reminder that attackers do not only chase laptops and email accounts. They target the systems that decide who gets access and whether the business can recover. Cisco ISE and Acronis Backup sit in categories that deserve elevated priority: identity control and recovery control.

If your organization uses either affected product, verify exposure, patch or mitigate, perform forensic triage, and document evidence. If you do not use them, review the equivalent control-plane systems in your environment. The lesson is bigger than two CVEs: the systems that control access and recovery need the fastest response, the best logs, and the clearest ownership.

FAQ

Is CVE-2026-76460 only a federal agency problem?

No. CISA’s binding operational directives apply to federal civilian executive branch agencies, but the KEV Catalog is intended to help the broader cybersecurity community prioritize vulnerabilities that are exploited in the wild. Private companies, healthcare organizations, schools, and local governments should still use KEV status as a strong prioritization signal.

Is the Acronis Backup issue remotely exploitable?

NVD describes CVE-2026-87886 as local privilege escalation due to insecure file permissions affecting specific Linux backup plugin and extension builds. That is different from unauthenticated remote exploitation. However, local privilege escalation can still be serious when an attacker already has a foothold on a hosting or backup-adjacent system.

Should we patch first or investigate first?

Do both, but do not let investigation delay containment. Restrict exposed management access immediately, apply vendor mitigations or updates, and preserve logs before they rotate. For KEV-listed identity and backup systems, remediation without triage leaves a major unanswered question: was the system abused before the patch?

What if our backup product is not Acronis?

Review your backup platform anyway. Confirm administrative access controls, MFA, logging, immutable or protected retention, backup-job integrity, restore testing, and separation of duties. The broader lesson is that backup infrastructure should be treated as security-critical, not just operations software.

Where can Datapath help?

Datapath helps regulated and mid-market organizations assess exposure, prioritize exploited vulnerabilities, harden management planes, document remediation evidence, and strengthen disaster recovery. Start with a cybersecurity risk assessment or review Datapath’s disaster recovery services if restore confidence is the primary concern.

Footnotes

  1. CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” release date September 16, 2026. Source 2

  2. CISA, “Known Exploited Vulnerabilities Catalog,” entries for CVE-2026-76460 and CVE-2026-87886, accessed September 18, 2026. Source 2 3 4

  3. NIST National Vulnerability Database, “CVE-2026-76460 Detail,” Cisco Identity Services Engine authentication bypass description and CNA severity information. Source

  4. NIST National Vulnerability Database, “CVE-2026-87886 Detail,” Acronis Backup affected products, build information, and CNA severity information. Source 2

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation