CISA's list that day

16 September 2026

On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Google Pixel, Cisco Identity Services Engine and Acronis Backup. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-76460Incorrect Use of Privileged APIsCisco Identity Services EnginePatch nowForensic triage required by CISA0.14
CVE-2026-58704Improper AuthorizationGoogle PixelPatch nowForensic triage required by CISA0.01
CVE-2026-87886Incorrect Default PermissionsAcronis BackupPatch nowForensic triage required by CISA0.00

Other changes that day

  1. CVE-2026-42016 JFrog ArtifactoryEdited: description.
  2. CVE-2026-67277 MikroTik RouterOSEdited: description.
  3. CVE-2026-84869 ConnectWise ScreenConnectEdited: description.
  4. CVE-2026-86060 MikroTik RouterOSEdited: description.
  5. CVE-2026-86060 MikroTik RouterOSEdited: notes.