CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google disclosed that vulnerability CVE-2026-58704 in the Pixel cellular modem was used in targeted attacks. CISA added it to the KEV catalog and required US federal agencies to fix the issue within three days.
- CVE-2026-58704 is a privilege bypass in the Pixel modem requiring no user action
- Google noted signs of limited targeted exploitation of the vulnerability
- CISA requires federal agencies to patch within three days
- The patch was included in the September Pixel update with 100+ fixes
Read next
Security