
SANS ISC Reports Multiple Critical Vulnerabilities: Cisco ISE, Acronis Backup, and Hospitality PBX Systems Under Attack
The SANS Internet Storm Center recorded on September 17th, 2026 reports on coordinated attacks targeting the hospitality industry and PBX phone systems, specifically probing for a product called PBX in a flash hospitality management system with a GitHub repository last updated 14 years ago that contains SQL injection vulnerabilities and lacks authentication controls. The attacks use a unique user agent Faress-Sorder and target various hotel management URLs. Cisco released an advisory for a CVSS score 10 authentication bypass vulnerability in their Identity Services Engine where the API fails to check all endpoints, and this vulnerability has already been exploited in the wild. Acronis published updates fixing vulnerabilities in their backup software plug-in for cPanel and Plesk, including a privilege escalation vulnerability currently being exploited, with updates released 5 days prior to the recording. Google published its September Pixel update bulletin containing a fix for an elevation of privilege vulnerability in their modem code, released one week after the general Android updates. SANS published a free ebook on incident response authored by Josh Wright who teaches the SEC 504 class.