What to patch now — 21 September 2026
Source: CISA Known Exploited Vulnerabilities (KEV) catalog — the most recently added entries as of today. Every vulnerability below has been confirmed by CISA as actively exploited in the wild, meaning attackers are already using it, not just researching it. If you (or a supplier) run any of this software, treat it as urgent.
A quiet week: CISA added only six new entries since last Monday's edition — well below a typical week — so this list is shorter than usual. That's the catalog being quiet, not us leaving anything out.
1. Google Pixel — a modem bug lets malicious code already on the phone grab higher-level control (CVE-2026-58704)
🛠️ Google Pixel devices · added 16 Sep 2026 · CISA fix-by date 19 Sep 2026 (2 days overdue)
What it is: "Improper authorization" means a logic error in the phone's cellular modem software fails to properly check what a piece of code is allowed to do. It doesn't let an attacker break into the phone from nowhere — but if something malicious is already running on it (say, from a dodgy app), this bug lets it climb from limited access to a much more privileged level.
Who's affected: Any business where staff carry a Google Pixel phone for work.
What to do: Install this month's Android security update on any Pixel used for business — it lands through the normal over-the-air update, so this is a "check it's actually installed" job rather than a technical one.
2. Cisco Identity Services Engine — a flaw lets an attacker skip the login screen entirely (CVE-2026-76460)
🛠️ Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector · added 16 Sep 2026 · CISA fix-by date 19 Sep 2026 (2 days overdue)
What it is: ISE is the system some networks use to decide who and what is allowed to connect — staff laptops, guest Wi-Fi, company phones. This bug misuses a privileged internal interface in a way that lets an attacker with no login at all bypass the web-based management screen and get in directly.
Who's affected: Mostly larger networks and the IT providers who manage them — ISE is enterprise-grade network-access software, not something a small office runs itself. But if a managed-service provider uses it to control who connects to your network, their compromise can become yours.
What to do: Apply Cisco's fix — the deadline has passed. If a managed-service provider looks after your network access, ask them directly whether Identity Services Engine is part of it and whether it's patched.
3. Acronis Backup (cPanel & Plesk) — a backup tool bundled with cheap web hosting was installed with the wrong permissions (CVE-2026-87886)
🛠️ Acronis Backup plugin for cPanel & WHM, and extension for Plesk · added 16 Sep 2026 · CISA fix-by date 19 Sep 2026 (2 days overdue)
What it is: cPanel and Plesk are the control panels most budget web hosts give small businesses to manage their own site. Acronis Backup is a common plug-in for taking automatic backups through that panel. "Incorrect default permissions" means the plug-in was set up in a way that lets an attacker escalate to a higher level of access than they should have on the server.
Who's affected: Any small e-shop or website on shared hosting where the host runs cPanel or Plesk with the Acronis Backup add-on — a very ordinary, budget-friendly hosting setup.
What to do: You likely can't patch this yourself — it lives on the hosting server, not your own computer. Ask your web host (or whoever manages your hosting account) whether they run Acronis Backup on cPanel/WHM or Plesk, and whether it's been updated.
4. Linux Kernel — three separate flaws added this week, two flagged as affecting older, unsupported versions (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
🛠️ Linux Kernel · added 18 Sep 2026 · CISA fix-by date 21 Sep 2026 (due today)
What it is: The kernel is the core of the Linux operating system that quietly runs most web servers, hosting platforms, small NAS storage boxes and even some routers. These three unrelated bugs — a race condition in encryption socket handling, a memory-overflow bug in a network address-translation feature, and a mishandled edge case in encrypted (TLS) network traffic — can each be used to destabilise or gain unauthorized access to the system. CISA notes that the versions affected by two of the three could be end-of-life, meaning some of the exposure is on Linux systems that are no longer getting routine updates at all.
Who's affected: Not something you'd patch on a laptop — this affects the Linux servers underneath web hosting, cloud infrastructure, and some network hardware. Relevant if your business runs its own Linux server, VPS or NAS device, or if your hosting/IT provider does on your behalf.
What to do: Ask your host or IT provider to confirm their Linux systems are on a currently-supported version and up to date. If you run a server or NAS yourself and don't know its Linux version, that's worth finding out — an end-of-life system won't get a fix for this at all.
This is an awareness summary of public CISA KEV data, not professional security advice. CISA "fix-by" dates are US federal deadlines; for everyone else they're a strong urgency signal, not a legal obligation. Always confirm the affected versions and the fix against the vendor's own advisory.