Skip to content
TrustList
News

Three more products join CISA's exploited list — remediation deadlines already passed

Editorial

By TrustList Editorial

CISA added Cisco ISE and Acronis Backup on 16 September (due 19th) and Zyxel's GS1900 switches on 21 September (due 24th); all three federal deadlines have now passed, and each flaw is confirmed exploited.

About Three more products join CISA's exploited list — remediation deadlines already passed

Three more products join CISA's exploited list — remediation deadlines already passed

21 September 2026 — The US Cybersecurity and Infrastructure Security Agency added three more flaws to its Known Exploited Vulnerabilities catalog in the past two weeks, each with evidence of active exploitation: Cisco Identity Services Engine and Acronis Backup on 16 September 2026, and Zyxel's GS1900 series switches on 21 September. This item is a catch-up: the catalog's own required-action dates for all three — 19 September for the first two, 24 September for the third — have already passed as of 26 September, so any organisation running these products that has not yet patched is already overdue, not merely on notice.

The three flaws

  • CVE-2026-76460 — Cisco Identity Services Engine. An incorrect-use-of-privileged-APIs flaw. ISE is enterprise software many organisations use to control who and what can join their network, making a flaw in it more consequential than a typical single-product bug.
  • CVE-2026-87886 — Acronis Backup. An incorrect-default-permissions flaw in a widely used enterprise backup product — the kind of flaw that can matter most in exactly the moment you need backups to be trustworthy.
  • CVE-2026-7273 — Zyxel GS1900 series switches. A stack-based buffer overflow in network switches used in small and mid-sized business networks.

What to do if you run any of these

  • Confirm you are on a patched version of Cisco ISE, Acronis Backup or Zyxel GS1900 firmware; CISA's directive to federal agencies (BOD 26-04) also asks agencies to check whether a system was compromised before the patch was applied, which is good practice for any organisation, not only federal ones.
  • Treat "the deadline already passed" as a reason to check now, not to skip the item — CISA lists a flaw only once exploitation is already confirmed, so the risk did not go away when the date did.
  • If any of these three products sit on a network segment you cannot immediately patch, isolate it from the internet-facing network in the meantime, which is CISA's standard interim advice for known-exploited flaws on assets that cannot be patched right away.

Sources