Three more products join CISA's exploited list — remediation deadlines already passed
EditorialBy TrustList Editorial
CISA added Cisco ISE and Acronis Backup on 16 September (due 19th) and Zyxel's GS1900 switches on 21 September (due 24th); all three federal deadlines have now passed, and each flaw is confirmed exploited.
About Three more products join CISA's exploited list — remediation deadlines already passed
Three more products join CISA's exploited list — remediation deadlines already passed
21 September 2026 — The US Cybersecurity and Infrastructure Security Agency added three more flaws to its Known Exploited Vulnerabilities catalog in the past two weeks, each with evidence of active exploitation: Cisco Identity Services Engine and Acronis Backup on 16 September 2026, and Zyxel's GS1900 series switches on 21 September. This item is a catch-up: the catalog's own required-action dates for all three — 19 September for the first two, 24 September for the third — have already passed as of 26 September, so any organisation running these products that has not yet patched is already overdue, not merely on notice.
The three flaws
- CVE-2026-76460 — Cisco Identity Services Engine. An incorrect-use-of-privileged-APIs flaw. ISE is enterprise software many organisations use to control who and what can join their network, making a flaw in it more consequential than a typical single-product bug.
- CVE-2026-87886 — Acronis Backup. An incorrect-default-permissions flaw in a widely used enterprise backup product — the kind of flaw that can matter most in exactly the moment you need backups to be trustworthy.
- CVE-2026-7273 — Zyxel GS1900 series switches. A stack-based buffer overflow in network switches used in small and mid-sized business networks.
What to do if you run any of these
- Confirm you are on a patched version of Cisco ISE, Acronis Backup or Zyxel GS1900 firmware; CISA's directive to federal agencies (BOD 26-04) also asks agencies to check whether a system was compromised before the patch was applied, which is good practice for any organisation, not only federal ones.
- Treat "the deadline already passed" as a reason to check now, not to skip the item — CISA lists a flaw only once exploitation is already confirmed, so the risk did not go away when the date did.
- If any of these three products sit on a network segment you cannot immediately patch, isolate it from the internet-facing network in the meantime, which is CISA's standard interim advice for known-exploited flaws on assets that cannot be patched right away.
Sources
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog — 16 September 2026
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog — 21 September 2026
- CISA Known Exploited Vulnerabilities catalogue, JSON feed (read 26 September 2026) — 26 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.