CISA KEV Alert 16 Sept 2026, 14:01 UTC

Actively Exploited Pixel Modem Flaw Bypasses Permission Checks

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities (KEV) catalogue on 16 September 2026. The vulnerability affects Google Pixel devices and is an improper authorisation flaw in the cellular modem that may allow attackers to bypass permission checks and escalate privileges.

The flaw results from a logic error in the modem’s authorisation controls. An attacker could exploit it to circumvent permission checks and gain higher privileges. NVD assigns the vulnerability a CVSS score of 8.0, rated High. Patch status is currently unknown, and no patch or advisory is listed in the supplied data.

KEV inclusion confirms that attackers are actively exploiting the vulnerability. Use in ransomware campaigns is unknown. CISA set 19 September 2026 as the remediation deadline for affected federal agencies.

CISA requires organisations to apply mitigations in accordance with vendor instructions, BOD 26-04 guidance on prioritising security updates based on risk, and its Forensics Triage Requirements. FCEB agencies are directly affected by this requirement. Stakeholders must assess each asset’s internet exposure and follow applicable BOD 26-04 patching guidance, or discontinue use of the product if mitigations are unavailable. All organisations should review their exposure to Google Pixel devices.

See the NVD entry and CISA KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-58704.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline