【Vulnerability Alert】CISA Added 7 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/14-2026/09/20)

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026092404091717 Publication Time 2026-09-24 16:18:18
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-24 16:18:18
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 7 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/14-2026/09/20)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000022

【CVE-2026-76461】Cisco Secure Email Gateway SQL Injection Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Cisco AsyncOS Software for Cisco Secure Email Gateway contains an SQL Injection vulnerability. An unauthenticated remote attacker may exploit this vulnerability to execute arbitrary commands with root privileges on the underlying operating system.

【CVE-2026-58704】Google Pixel Improper Authorization Vulnerability (CVSS v3.1: 8.8)
【Whether exploited by ransomware: Unknown】The mobile communications modem in Google Pixel devices contains an Improper Authorization vulnerability. This logic error may allow an attacker to bypass permission checks and escalate privileges.

【CVE-2026-76460】Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an Incorrect Use of Privileged APIs vulnerability, which may allow an unauthenticated remote attacker to bypass the web management interface and thereby gain unauthorized access to affected devices.

【CVE-2026-87886】Acronis Backup Incorrect Default Permissions Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】The cPanel & WHM plugin and Plesk extension of Acronis Backup contain an Incorrect Default Permissions vulnerability, which may result in privilege escalation.

【CVE-2025-39964】Linux Kernel Race Condition Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】Linux Kernel contains a Race Condition vulnerability that allows concurrent writes to the same AF_ALG socket, causing data to be interleaved unpredictably and resulting in inconsistent internal socket state.

【CVE-2026-53266】Linux Kernel Out-of-Bounds Write Vulnerability (CVSS v3.1: 8.8)
【Whether exploited by ransomware: Unknown】The ebtables SNAT target in Linux Kernel contains an Out-of-Bounds Write vulnerability. This vulnerability allows rewriting of the ARP sender hardware address to write directly into nonlinear socket buffer fragments backed by file pages imported through splice. The affected products may have reached End-of-Life (EoL) or End-of-Support (EoS). Users are advised to discontinue use of the affected products or migrate to supported versions.

【CVE-2025-39682】Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】The TLS receive path in Linux Kernel contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A zero-length record retrieved from rx_list may bypass the expected recvmsg() record-type handling mechanism, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queue assumptions. The affected products may have reached End-of-Life (EoL) or End-of-Support (EoS). Users are advised to discontinue use of the affected products or migrate to supported versions.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-76461】Please refer to the affected versions listed by the official vendor:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

【CVE-2026-58704】Please refer to the affected versions listed by the official vendor:
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01

【CVE-2026-76460】Please refer to the affected versions listed by the official vendor:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

【CVE-2026-87886】Please refer to the affected versions listed by the official vendor:
https://security-advisory.acronis.com/advisories/SEC-10986

【CVE-2025-39964】Please refer to the affected versions listed by the official vendor:
https://lore.kernel.org/linux-cve-announce/2025101334-CVE-2025-39964-7964@gregkh/

【CVE-2026-53266】Please refer to the affected versions listed by the official vendor:
https://lore.kernel.org/linux-cve-announce/2026062517-CVE-2026-53266-6162@gregkh/

【CVE-2025-39682】Please refer to the affected versions listed by the official vendor:
https://lore.kernel.org/linux-cve-announce/2025090545-CVE-2025-39682-ddab@gregkh/

[Recommended Actions]

【CVE-2026-76461】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

【CVE-2026-58704】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01

【CVE-2026-76460】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

【CVE-2026-87886】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://security-advisory.acronis.com/advisories/SEC-10986

【CVE-2025-39964】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://lore.kernel.org/linux-cve-announce/2025101334-CVE-2025-39964-7964@gregkh/

【CVE-2026-53266】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://lore.kernel.org/linux-cve-announce/2026062517-CVE-2026-53266-6162@gregkh/

【CVE-2025-39682】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
https://lore.kernel.org/linux-cve-announce/2025090545-CVE-2025-39682-ddab@gregkh/

 

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center