Skip to content
Warning about cyberattacks on Google Pixel, Cisco ISE, and Acronis Backup

Warning about cyberattacks on Google Pixel, Cisco ISE, and Acronis Backup

Heise.De September 17, 2026

Cybercriminals exploit security vulnerabilities in Google Pixel, Cisco Identity Services Engine (ISE), and Acronis Backup. Updates to fix two of the vulnerabilities have only recently become available. IT managers and administrators should act quickly, install the updates, and investigate internet-accessible devices for possible attacks.

The US cybersecurity agency CISA warns of these issues in two security advisories. The first addresses a new, previously unknown vulnerability in Cisco’s Identity Services Engine (ISE) that allows authentication bypass and has the highest risk rating (CVE-2026-76460, CVSS 10.0 , Risk “ critical ”). Cisco states that unauthenticated attackers from the internet can exploit insufficient control in an API endpoint, and according to Cisco’s findings, this is already happening in the wild. The manufacturer also provides indicators of successful attacks that administrators can for. Cisco ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4 fix the security vulnerability.

The second vulnerability affects Acronis Backup for cPanel/WHM and Plesk. Acronis already issued a warning on Wednesday ongoing attacks and is delivering updated software to patch the vulnerabilities.

A second advisory from CISA concerns Google’s Pixel smartphones. Google released an operating system update for these on Tuesday night that closes several security vulnerabilities, some of which are classified as critical. The update for vulnerability CVE-2026-58704 , however, patches a flaw in the mobile modem that allows logic errors in the code to bypass authorization limits. This can lead to privilege escalation by malicious actors from the network without any interaction from the owners (CVSS according to CISA 8.8 , Risk “ high ”). Google states in the overview of the Pixel Android update that the vulnerability is being targeted to a limited extent.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.