www.cisa.gov 16 Sept 2026, 12:00 UTC

CISA Warns of Active Exploitation in Google Pixel Vulnerability

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-58704, described as a Google Pixel improper authorisation vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog on 16 September 2026. The agency said the addition was based on evidence of active exploitation, but did not provide further technical details about the flaw, affected Pixel versions, the attack method or the identity of the actors involved.

CISA said vulnerabilities in the catalogue are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Under Binding Operational Directive 26-04, US Federal Civilian Executive Branch agencies must prioritise remediation of KEV-listed vulnerabilities on publicly exposed assets that could give an attacker total control after exploitation, while deferring lower-risk work.

The directive also sets expectations for checking whether systems were compromised before a patch was applied. Although those requirements apply only to federal civilian agencies, CISA encouraged all organisations to use risk-based vulnerability management and prioritise KEV vulnerabilities.

Organisations should therefore review whether they use affected Google Pixel devices, apply available vendor mitigations or updates, and assess systems for possible compromise, although the notice provides no specific remediation steps.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline