$ techbeacon▋
CVE & Exploits

CISA Expands Exploited Vulnerabilities List to Include Acronis Backup, Cisco ISE and Google Pixel Flaws

CISA Expands Exploited Vulnerabilities List to Include Acronis Backup, Cisco ISE and Google Pixel Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include newly identified flaws affecting Acronis Backup software, Cisco's Identity Services Engine (ISE) and certain Google Pixel devices.

The KEV catalog is a central resource that federal agencies and private organizations use to prioritize patching and mitigation efforts for vulnerabilities that have been observed in the wild. By adding these three products, CISA signals that threat actors are actively exploiting weaknesses in widely deployed backup solutions, network authentication platforms and popular mobile hardware.

Acronis Backup is a common choice for data protection across enterprises and small businesses, while Cisco ISE serves as a cornerstone for network access control in many corporate environments. The inclusion of Google Pixel devices highlights the growing relevance of mobile operating systems in the attack surface, especially as they are used for both personal and work-related communications.

Although the agency has not disclosed technical details such as CVE identifiers or the specific attack vectors, the announcement underscores the urgency for organizations to verify that they have applied the latest security updates from each vendor. In past instances, exploitation of similar flaws has led to data exfiltration, unauthorized network access, and the deployment of ransomware.

CISA advises IT leaders to consult the catalog, cross‑reference their asset inventories, and accelerate remediation timelines where the listed products are in use. The agency also recommends employing layered defenses, including endpoint detection and response tools, network segmentation, and strict credential hygiene, to reduce the likelihood of successful exploitation.

Industry observers note that the addition of these entries reflects a broader trend of attackers targeting supply‑chain and infrastructure components that are integral to daily operations. As the threat landscape evolves, the KEV catalog will likely continue to expand, offering a transparent mechanism for the public and private sectors to stay aligned on emerging risks.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related