CISA's list that day
16 September 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Google Pixel, Cisco Identity Services Engine and Acronis Backup. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-76460Incorrect Use of Privileged APIs | Cisco Identity Services Engine | Patch nowForensic triage required by CISA | 0.14 | ||
| CVE-2026-58704Improper Authorization | Google Pixel | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-87886Incorrect Default Permissions | Acronis Backup | Patch nowForensic triage required by CISA | 0.00 |