Acronis Backup Is Actively Exploited. Your MSP Might Not Have Told You.
Three vulnerabilities landed on CISA’s Known Exploited Vulnerabilities catalogue overnight. One is in backup software. One is in network access control infrastructure. Both are technologies that managed service providers routinely operate on behalf of their clients.
If your MSP hasn’t contacted you about either of them, that is a data point worth recording.
What CISA Confirmed
On 16 September 2026, CISA added three vulnerabilities to its KEV catalogue. The KEV list is not a theoretical risk register. It is a list of vulnerabilities for which CISA has confirmed evidence of active exploitation in the wild. These are not hypotheticals.
CVE-2026-87886: Acronis Backup plugin for cPanel and Plesk. The flaw is an incorrect default permissions vulnerability in the Acronis Backup plugin used with two of the most common web hosting control panels. It allows privilege escalation. In plain terms: an attacker who gets a foothold in your hosting environment can use this to acquire higher-level access and move further through the system. Acronis Backup is used extensively by MSPs and hosting providers to manage backup processes on behalf of clients. If your backup is outsourced, this matters to you regardless of whether you know what cPanel is.
CVE-2026-76460: Cisco Identity Services Engine. This is an authentication bypass. CVSS score: 10.0. An unauthenticated, remote attacker can bypass the web-based management interface and gain unauthorised access to the device. Cisco ISE (Identity Services Engine) is a network access control product. It is the thing that decides who and what is allowed onto a network. Compromising it gives an attacker visibility into and control over network access policy. This is not a peripheral system. It is a trust anchor.
CVE-2026-58704: Google Pixel. An improper authorisation vulnerability in the cellular modem of Pixel devices. A logic error allows privilege escalation. If your staff use Pixel phones for work, particularly for accessing email or business applications, this requires attention.
The Cisco Situation Is Larger Than One CVE
The Acronis and Pixel entries are serious. The Cisco situation deserves separate attention.
Cisco published more than twenty critical and near-critical CVEs for its Identity Services Engine, Nexus Dashboard, Secure Firewall Management Center, and Adaptive Security Appliance products within a twenty-four hour window on 16 September. Several of these carry a CVSS score of 10.0, the maximum possible. That score indicates: no authentication required, no user interaction required, full impact on confidentiality, integrity, and availability.
To be precise about what some of these CVEs describe:
- CVE-2026-76423: An unauthenticated remote attacker can gain administrative access to Cisco ISE via the REST API. The attacker can read and modify ISE configuration and identity data with administrative privileges.
- CVE-2026-20242: An unauthenticated remote attacker can execute arbitrary commands as root on Cisco Secure Firewall Management Center via insecure deserialisation of a Java byte stream.
- CVE-2026-20324: An authenticated attacker can execute arbitrary commands as root on Cisco Secure FMC by exploiting incorrect write permissions in the sftunnel inter-device communication protocol.
These are not obscure edge cases. They are central infrastructure systems with maximum-severity vulnerabilities, several of which require no credentials to exploit.
For UK small businesses, the direct exposure to enterprise Cisco infrastructure is limited. The indirect exposure is not. If your MSP uses Cisco ISE to manage network access across its client estate, a compromise of that ISE deployment is a supply chain risk to every client on that estate. That includes you.
Why the Acronis Angle Matters Most to SMBs
Backup software occupies a specific position in the attack surface of a small business. It is trusted. It has access to everything worth protecting. It is typically managed by a third party. And it is almost never monitored by the client.
The attack pattern for ransomware groups has evolved. The objective is no longer simply to encrypt files. It is to find and neutralise backup systems first, then encrypt, then demand payment. A backup plugin with a privilege escalation vulnerability is a useful tool in that sequence.
If your backup is managed by an MSP using Acronis Backup, the relevant questions are:
- Has the Acronis Backup plugin been patched to a version that addresses CVE-2026-87886?
- Has the MSP confirmed in writing that the patch has been applied across all systems managing your data?
- When was your backup last tested by actually restoring from it?
If you cannot get a clear written answer to question one within 48 hours, that is a contractual and operational concern, not just a technical one.
How to Use This as a Competitive Signal
Every client your MSP is failing to call this week is a client who will eventually find a provider who does call. Proactive vulnerability communication is not a premium service. It is a baseline expectation that the market is slowly learning to enforce.
For businesses that do receive a clear, timely communication from their MSP about this week’s KEV additions: document it. That is evidence of a functioning security relationship. It is the kind of evidence that matters in procurement conversations, in insurance renewals, and in post-incident reviews.
For businesses that do not receive that communication: the absence is also evidence. Use it accordingly.
Making the Case Internally
Three arguments for getting budget or management attention on this:
The regulator’s position is clear. The NCSC advises UK organisations to apply patches for actively exploited vulnerabilities as a priority. CISA’s KEV catalogue is one of the most reliable signals of active exploitation. These are not advisory recommendations from a vendor with a product to sell. They are confirmed exploitation events reported by the US government’s cybersecurity agency.
Backup compromise is recoverable. Backup destruction is not. The distinction matters when framing risk for a board or senior management. A ransomware attack against encrypted, tested, offsite backups is survivable. A ransomware attack that has already neutralised the backup system is an existential event for many small businesses.
Your MSP contract almost certainly includes patching obligations. Most managed service agreements include language about patch management and security updates. CVE-2026-87886 being on the CISA KEV list means it has moved from ‘should patch’ to ‘must patch under any reasonable interpretation of due care.’ Check your contract. Ask for written confirmation of compliance.
What to Do Before the End of This Week
Contact your MSP today. Ask specifically about CVE-2026-87886 (Acronis Backup) and CVE-2026-76460 (Cisco ISE). Use the CVE numbers. If they don’t know what you’re referring to, that is diagnostic.
Request written confirmation of patch status. An email will do. You want a record that you asked and what you were told. If something goes wrong later, that record matters.
Check your Pixel devices. CVE-2026-58704 affects Google Pixel devices. If staff use Pixel phones for work email, Teams, or any business application, check for system updates: Settings, Security and emergency, Security update. Apply immediately.
Test your backup. Not conceptually. Actually restore a file from your most recent backup and confirm it works. If you cannot do this yourself, ask your MSP to demonstrate it and document the result.
Audit your browser extensions. Separate from today’s KEV stories, researchers published proof-of-concept work this week showing that a single malicious browser extension can hijack AI assistants across Chrome, Edge, and related browsers. If your staff use AI tools in the browser for business purposes, review which extensions are installed and remove any that are not explicitly authorised.
The threats published yesterday are being exploited today. The question is not whether patching is a priority. The question is whether your MSP is treating it as one.
Before you go: follow the show wherever you listen, and leave a rating or review if this has been useful. Drop a comment with your thoughts, particularly if you’ve had a conversation with your MSP this week that went well or badly. And if you know a business owner who should be asking these questions, share this with them.