CISA Adds Cisco ISE and Acronis Backup Flaws to KEV; WooCommerce WordPress Plugin Under Active Attack
CISA adds actively exploited Cisco ISE and Acronis Backup flaws to KEV; WooCommerce WordPress plugin RCE under attack. Patch and harden now.
- CISA added CVE-2026-76460 (Cisco ISE) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
- Acronis confirmed the cPanel/WHM and Plesk backup plugin flaw is exploited in targeted attacks; Cisco ISE has an unauthenticated management interface bypass.
- Attackers are actively exploiting a critical RCE in the WooCommerce Wholesale Lead Capture plugin; two critical flaws in The Events Calendar are disclosed and should be patched as a precaution, but are not confirmed exploited.
What to do now
- Patch Cisco ISE (CVE-2026-76460) and the Acronis Backup plugin for cPanel/WHM and Plesk (CVE-2026-87886) per vendor advisories; if no patch exists yet, apply mitigations or isolate affected systems.
- Restrict Cisco ISE management interfaces to trusted admin networks and avoid exposing them directly to the internet while you verify patch status with Cisco.
- For Acronis, review and correct file and directory permissions, limit local access to backup interfaces, and monitor for privilege-escalation activity.
- For WordPress, update or remove WooCommerce Wholesale Lead Capture immediately and scan for PHP web shells; patch The Events Calendar as a precaution and block PHP execution in upload directories.
- Monitor logs for exploitation indicators and verify all actions against the vendor advisories and any applicable CISA remediation timelines.