CISA Adds Cisco ISE and Acronis Backup Flaws to KEV; WooCommerce WordPress Plugin Under Active Attack

CISA adds actively exploited Cisco ISE and Acronis Backup flaws to KEV; WooCommerce WordPress plugin RCE under attack. Patch and harden now.

  • CISA added CVE-2026-76460 (Cisco ISE) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
  • Acronis confirmed the cPanel/WHM and Plesk backup plugin flaw is exploited in targeted attacks; Cisco ISE has an unauthenticated management interface bypass.
  • Attackers are actively exploiting a critical RCE in the WooCommerce Wholesale Lead Capture plugin; two critical flaws in The Events Calendar are disclosed and should be patched as a precaution, but are not confirmed exploited.

What to do now

  1. Patch Cisco ISE (CVE-2026-76460) and the Acronis Backup plugin for cPanel/WHM and Plesk (CVE-2026-87886) per vendor advisories; if no patch exists yet, apply mitigations or isolate affected systems.
  2. Restrict Cisco ISE management interfaces to trusted admin networks and avoid exposing them directly to the internet while you verify patch status with Cisco.
  3. For Acronis, review and correct file and directory permissions, limit local access to backup interfaces, and monitor for privilege-escalation activity.
  4. For WordPress, update or remove WooCommerce Wholesale Lead Capture immediately and scan for PHP web shells; patch The Events Calendar as a precaution and block PHP execution in upload directories.
  5. Monitor logs for exploitation indicators and verify all actions against the vendor advisories and any applicable CISA remediation timelines.