Secret CISO 9/17: Pixel Zero-Click, Cisco ISE Bypass, Acronis LPE, WordPress RCE
Zero-click Pixel modem exploits meet a max-severity Cisco ISE auth bypass, while attackers go after the thing you rely on most: backups. Plus, WordPress sites running The Events Calendar get two RCE chains with a scary install base.
Today’s theme is painfully simple: attackers keep winning by living in your “trust layer”, the mobile modem you never patch fast enough, the identity gate you assumed was safe, and the backup tooling you installed to survive ransomware.
Today's Top 5
- Pixel zero-click in the wild: Google patched CVE-2026-58704, a Pixel modem bug used in targeted attacks with no taps, no clicks, no “user awareness training.” The scary part is what it implies about device-level visibility.
- Cisco ISE auth bypass is 10/10: Cisco shipped an API authentication bypass in Identity Services Engine, CVE-2026-76460 (CVSS 10.0). If ISE is your trust anchor, this is a bad day.
- Backups as the privilege ladder: Acronis confirmed exploitation of CVE-2026-87886, a local privilege escalation in its cPanel and Plesk backup extensions. The twist is where attackers start once they own the backup path.
- 240K WordPress sites: RCE chains: Two unauthenticated chains in The Events Calendar include CVE-2026-78006 (CVSS 9.8). If comments are on, attackers may not need an account, just patience.
- Iran-linked spyware uses Telegram: A joint advisory says Iranian operators deploy “Chosen Brick” Windows malware and use unique Telegram bot IDs for C2. The detail you should obsess over is the operational discipline.
Why today matters: We are watching the attack surface migrate upward into control planes and “security plumbing.” Modems, identity brokers, and backup plugins are the new quiet front doors. If your detection strategy still assumes the compromise starts at a phish, your incident timeline will be wrong, and so will your spend.
Alright, let’s get specific.
Data Breaches

- Premier Medical Group notifies 282,075 patients: New York provider Premier Medical Group says attackers accessed files on June 14 and exfiltrated patient data, with notification now underway. The dataset includes diagnoses, medications, insurance, and identifiers, which is exactly what fuels long-tail fraud and medical identity abuse. Source: SecurityWeek
- Spanish regulator logs first “agentic AI” breach report: SecurityWeek reports Spanish regulators received a notification describing an AI agent chaining login, vuln discovery, and access to personal data. Even if the “agentic” framing evolves, the operational reality is automated chaining is now normal for intrusions. Source: SecurityWeek
- Hospitals and critical services stay in the blast radius: The SANS ISC Stormcast flags current scanning and exploitation pressure across widely used products, a reminder that disruptions often precede formal breach notifications by weeks. Use this as your “what’s already knocking” barometer. Source: SANS Internet Storm Center
Security Research

- Pixel modem zero-day exploited (zero-click): Google disclosed and patched CVE-2026-58704 affecting Pixel phones’ modem, with CISA adding it to KEV and pushing an aggressive deadline. If you have executives on Pixel, treat this like a travel-risk item, not a routine patch. Source: The Register
- Cisco ISE unauthenticated auth bypass: Cisco published a critical advisory for CVE-2026-76460 (CVSS 10.0) enabling an unauthenticated remote attacker to bypass authentication in an API. If ISE touches NAC, guest, or device posture workflows, assume the blast radius is broader than “just one app.” Source: Cisco
- Acronis backup plugin LPE exploited: Acronis says exploitation of CVE-2026-87886 has been detected in limited targeted attacks against the cPanel and WHM plugin. In hosting and MSP environments, “local” often means “one compromised tenant away from root.” Source: BleepingComputer
- WordPress The Events Calendar: unauthenticated RCE chains: SecurityWeek covers two issues enabling unauthenticated RCE scenarios, including CVE-2026-78006 (9.8), impacting a large install base when certain settings are enabled. For many orgs, the problem is not WordPress, it is the one marketing microsite nobody owns. Source: SecurityWeek
- Iranian “Chosen Brick” malware tradecraft: US, UK, and Dutch agencies published a joint advisory describing a Windows malware family used against dissidents, journalists, and activists, including C2 via unique Telegram bot IDs. It is a strong example of adversaries adopting “consumer platform” resilience. Source: SecurityWeek
Top CVEs

- CVE-2026-58704: Pixel modem vulnerability exploited in targeted zero-click attacks. Impact includes privilege escalation from the modem context into broader device data, with urgent patch pressure after KEV listing. Source
- CVE-2026-76460: Cisco Identity Services Engine API authentication bypass (CVSS 10.0). Unauthenticated remote bypass in a central identity and access control component can turn segmented networks into a single trust domain. Source
- CVE-2026-87886: Acronis Backup plugin/extension local privilege escalation due to insecure file permissions, with reported in-the-wild exploitation. Treat as a post-compromise accelerator on shared Linux hosts and control panels. Source
- CVE-2026-78006: The Events Calendar WordPress plugin unauthenticated PHP object injection leading to RCE (CVSS 9.8) under common configurations. This is the kind of plugin exposure that gets you owned through a “non-critical” web property. Source
- CVE-2026-85706: GitLab max-severity issue added to CISA KEV, with active exploitation reported. If you host GitLab, prioritize patch validation and token hygiene, because the second-order impact is credential reuse and CI secret theft. Source
Podcasts & Talks

- SANS Stormcast (Sep 17, 2026): Today’s episode stitches together the practical operator view of what is being scanned and exploited right now, including Cisco, Acronis, and Pixel items. This is useful for SOC leaders who need a daily “what’s hitting the perimeter” sanity check. Listen: SANS Internet Storm Center
- Risky Business #853 (Sep 16, 2026): A grounded discussion that pushes past AI doom headlines and focuses on supervision, fundamentals, and what actually changes a defender’s plan. Worth it if your board is asking for an “AI threat briefing” and you want something less theatrical. Listen: Risky Business
- CISO Series Podcast: “We Strongly Value Your Willingness to Accept Less” (Sep 15, 2026): A practical CISO-level conversation about patching reality, board risk acceptance, and how security teams communicate constraints without hand-waving. Good calibration for leaders who are tired of perfect-world remediation plans. Listen: CISO Series
Final Words
The uncomfortable pattern today is that “security tools” are increasingly just software with privileges, and attackers are treating them like ladders. The modem bug is a reminder that endpoint compromise can begin below the OS. The ISE bypass reminds us identity systems are now primary targets. The Acronis flaw is the punchline: the thing you count on after disaster is becoming part of the disaster plan.
This week, do three things:
- Patch and enforce update compliance for Pixel September 2026 updates to address CVE-2026-58704, and treat executive devices as a tracked risk item until verified installed.
- Validate Cisco ISE exposure and upgrade or mitigate immediately for CVE-2026-76460, then review ISE API access paths and any external reachability assumptions you forgot you made.
- Inventory hosting and MSP-managed servers for Acronis cPanel/WHM and Plesk integrations, patch for CVE-2026-87886, and review whether any “local” users can become root via shared tooling.
Your turn: If a zero-click modem exploit hit one of your executives on a work trip tomorrow, do you have a playbook that catches it before their phone becomes your MFA reset keychain? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.
Know someone who still treats ISE, backups, or a “marketing WordPress” as out of scope? Forward them this issue, it costs 30 seconds and the alternative costs a lot more. For forwarded and web readers: subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!