Daily Signal — 2026-09-17
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 5/5 sources were live for this edition.
At a glance
- CVE-2026-58704 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: CISA Adds One Known Exploited Vulnerability to Catalog.
- M6.5 was the strongest M4.5+ event in the USGS 24-hour feed.
- Long March 12 | SatNet LEO Group 25 is next on the public launch manifest.
Exploited vulnerabilities
- CVE-2026-58704 — Google Pixel. Added 2026-09-16; remediation due 2026-09-19. Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-76460 — Cisco Identity Services Engine. Added 2026-09-16; remediation due 2026-09-19. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-87886 — Acronis Backup. Added 2026-09-16; remediation due 2026-09-19. Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2026-58704 · Google Pixel · added 2026-09-16 · due 2026-09-19
- CVE-2026-76460 · Cisco Identity Services Engine · added 2026-09-16 · due 2026-09-19
- CVE-2026-87886 · Acronis Backup · added 2026-09-16 · due 2026-09-19
- CVE-2026-76461 · Cisco Secure Email Gateway · added 2026-09-14 · due 2026-09-17
- CVE-2026-84869 · ConnectWise ScreenConnect · added 2026-09-11 · due 2026-09-14
- CVE-2026-42016 · JFrog Artifactory · added 2026-09-11 · due 2026-09-25
- CVE-2026-42018 · JFrog Artifactory · added 2026-09-11 · due 2026-09-25
- CVE-2026-85706 · GitLab Community Edition and Enterprise Edition · added 2026-09-11 · due 2026-09-14
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- The current CISA advisory window contains no title or summary that explicitly names a threat actor, campaign, or ransomware operation.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M6.5 — 165 km W of Nikolski, Alaska, 2026-09-17 14:19 UTC. The M4.5+ day feed contained 15 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- Long March 12 | SatNet LEO Group 25 — China Aerospace Science and Technology Corporation; Launch Successful; no-earlier-than 2026-09-17 00:32 UTC. Pad: Commercial LC-2 · Wenchang Space Launch Site, People's Republic of China.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: live
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-17 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.