CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog, Including Cisco ISE and Acronis Backup Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities with confirmed exploitation in the wild to its Known Exploited Vulnerabilities (KEV) catalog. The additions were announced on September 16, 2026, with a mandatory remediation deadline of September 19 for all affected products.
Two of the flaws reside in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-76460, the vulnerability results from insufficient authentication controls on an API endpoint. Unauthenticated remote attackers can bypass the web-based management interface and gain unauthorized access to the affected appliances.
The third entry concerns Acronis Backup. The flaw, identified as CVE-2026-87886, affects the plugin for cPanel & WHM and the extension for Plesk. Default access permissions are configured too permissively, allowing attackers to escalate privileges on the server.
CISA is urging all federal civilian agencies to prioritize investigation of potential intrusions and to apply available mitigations or patches by the stated deadline.
Related articles
WordPress 7.1.3 Security Release Fixes Seven Vulnerabilities Including Stored XSS and SQL Injection
The WordPress development team has released version 7.1.3 as a maintenance and security update addressing multiple vulnerabilities. The release includes seven security fixes and four additional bug corrections. Among the security issues resolved is a stored cross-site scripting flaw that allowed pending comments to execute scripts in the administrative interface. Other fixes cover a denial-of-service condition in URL handling, an SQL injection vulnerability in the WXR export feature, and unauthorized disclosure of comments attached to private or unpublished posts. Additional patches address an XSS issue in the Imgur embed functionality, improper sticky post permissions for users with the Author role, and a parameter manipulation problem affecting hook action names.
Google Releases Chrome 155 Fixing 247 Vulnerabilities Including Four Critical Use-After-Free Flaws
Google has released Chrome 155 on October 6, 2026, addressing a total of 247 security issues across Windows, macOS, and Linux platforms. The update includes four critical vulnerabilities, all classified as use-after-free flaws that affect Chromecast, Browser, Navigation, and Track components. Fifty-three high-severity issues were also resolved, covering problems in SiteIsolation, Core, Omnibox, FileSystem, ANGLE, WebGL, and multiple other modules. The critical CVEs fixed are CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. Additional fixes address use-after-free conditions, race conditions, type confusion, and integer overflows in V8, WebRTC, PDF, Media, Parser, Storage, and WebAudio. The new versions are Chrome 155.0.8059.40 for Windows and macOS and 155.0.8059.39 for Linux and macOS.
LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings
Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.
Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing
The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.