CVE Digest — September 16, 2026
13 CVE
3 KEV
Digest for September 16, 2026: 3 new entries in the CISA KEV catalog and 10 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Acronis: rilevato sfruttamento in rete della CVE-2026-87886
- Risolte vulnerabilità in prodotti HPE Networking
- Risolte vulnerabilità in prodotti Mozilla
- Risolte vulnerabilità nei prodotti Atlassian
- Critical Patch Update di Oracle
- Risolte vulnerabilità in MISP
- Aggiornamenti di sicurezza per dispositivi Google Pixel
- Risolte vulnerabilità in Google Chrome
- Risolte vulnerabilità in Squid
- Risolta vulnerabilità in Mattermost
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-58704 KEV | Google Pixel | – | Unknown | CVE-2026-58704: Google Pixel cellular modem has an improper authorization flaw. A logic error may let an attacker bypass permission checks and escalate privileges. Apply vendor mitigations per CISA BOD 26-04. Added to KEV 2026-09-16. | |
| CVE-2026-76460 KEV | Cisco Identity Services Engine | – | Unknown | CVE-2026-76460: Cisco ISE and ISE-PIC misuse privileged APIs, letting an unauthenticated remote attacker bypass the web-based management interface and gain unauthorized access to the device. Apply vendor mitigations per CISA BOD 26-04. Added to KEV 2026-09-16. | |
| CVE-2026-87886 KEV | Acronis Backup | – | Unknown | CVE-2026-87886: Acronis Backup plugin for cPanel & WHM and extension for Plesk have incorrect default permissions, enabling privilege escalation. Apply vendor mitigations per CISA BOD 26-04. Added to KEV 2026-09-16. | |
| CVE-2026-87886 | – | – | Unknown | ACN reports active exploitation in the wild of CVE-2026-87886, already patched by the vendor. It affects Acronis Backup plugins for Plesk, cPanel and WHM and could let an attacker escalate privileges on affected systems. Published 2026-09-16. | |
| risolte-vulnerabilita-in-prodotti-hpe-networking | – | – | Unknown | ACN: HPE released security updates fixing 39 vulnerabilities (6 critical, 18 high) in HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator. Apply updates promptly. Published 2026-09-16. | |
| risolte-vulnerabilita-in-prodotti-mozilla-10 | – | – | Unknown | ACN: Mozilla security updates fix multiple vulnerabilities (33 rated high) in Firefox, Firefox ESR and Thunderbird. Apply the latest updates promptly. Published 2026-09-16. | |
| risolte-vulnerabilita-nei-prodotti-atlassian | – | – | Unknown | ACN: Atlassian updates fix one high-severity vulnerability in Crowd Data Center that could let an unauthenticated attacker bypass authentication and access restricted features or resources. Apply updates. Published 2026-09-16. | |
| critical-patch-update-di-oracle-11 | – | – | Unknown | ACN: Oracle released its September Critical Patch Update fixing numerous vulnerabilities across many products, including 97 critical and 485 high severity. Apply the patch update promptly. Published 2026-09-16. | |
| risolte-vulnerabilita-in-misp | – | – | Unknown | ACN: MISP updates fix multiple vulnerabilities (one critical, two high) in the open-source threat intelligence platform. Exploitation could let an attacker bypass authentication and security controls and access sensitive information. Apply updates. Published 2026-09-16. | |
| aggiornamenti-di-sicurezza-per-dispositivi-google-pixel-7 | – | – | Unknown | ACN: Google’s September security updates fix multiple vulnerabilities (46 critical, 63 high) in Pixel devices. Apply the latest firmware updates promptly. Published 2026-09-16. | |
| risolte-vulnerabilita-in-google-chrome-73 | – | – | Unknown | ACN: Google released a Chrome update fixing 42 security vulnerabilities (3 critical, 28 high). Apply the latest browser update promptly. Published 2026-09-16. | |
| risolte-vulnerabilita-in-squid | – | – | Unknown | ACN: Squid updates fix three vulnerabilities (one high) in the open-source caching proxy. Exploitation could let an attacker bypass security features and alter cached content via crafted HTTP requests. Apply updates. Published 2026-09-16. | |
| risolta-vulnerabilita-in-mattermost | – | – | Unknown | ACN: Mattermost security updates fix one high-severity vulnerability in the collaboration and messaging platform. Exploitation could let authenticated malicious users bypass security restrictions on affected systems. Apply updates. Published 2026-09-16. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.