CISA Sets a 3-Day Deadline for an Exploited Pixel Flaw
Security / news
CISA Sets a 3-Day Deadline for an Exploited Pixel Flaw
The agency added CVE-2026-58704, a privilege-escalation bug in the Pixel's cellular modem that needs no password and no tap from the owner, to its exploited-vulnerabilities catalog Wednesday, and Google's own bulletin rates it High, not Critical.

An attacker within radio range of a Google Pixel phone can escalate privileges on the device without a password and without the owner tapping anything, and the Cybersecurity and Infrastructure Security Agency says someone is already doing it. CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog on Wednesday and gave federal civilian agencies until Saturday, Sept. 19, to apply Google's fix.
That three-day window is short even by CISA's own standard, which typically allows about three weeks under Binding Operational Directive 26-04. The agency's notice says agencies must apply mitigations or stop using the product if none are available, and evaluate each asset's exposure to the internet, according to CISA's catalog entry for the vulnerability.
What the flaw allows
Google's September Pixel bulletin, published Sept. 15, describes CVE-2026-58704 as a logic error in the cellular modem that lets an attacker bypass a permission check and escalate privileges. The attack vector is rated adjacent network, meaning the attacker needs proximity to the device, such as a rogue base station, rather than a connection from anywhere on the internet. No privileges and no user interaction are required, and the National Vulnerability Database scores it 8.8 out of 10, High severity, with a vector of AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
The bulletin carries a one-line warning not attached to most of its other entries: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation." Google's own patch-level guidance says devices running the Sept. 5, 2026 security patch level or later are protected.
The score understates the story
Google's September bulletin fixed 109 vulnerabilities in total: 54 rated Critical, 54 rated High and one Moderate. CVE-2026-58704 sits in the High tier, below three dozen Critical-rated bootloader and trusted-execution flaws patched the same day. None of those Criticals appear on CISA's exploited list. The modem bug does, which is the opposite of what severity alone would predict.
- Critical54 CVEs
- High54 CVEs
- Moderate1 CVEs
Source: Android Security Bulletin, Pixel, September 2026, accessed 2026-09-16
What neither company nor agency has said
Google's bulletin does not say how many devices have been targeted, who is behind the activity, or how the exploitation was detected. CISA's catalog entry does not name a threat actor either; its required action is limited to patching or discontinuing use of the product. The technology outlet IntoMobile, in a separate write-up published the same day, speculated that the targeted pattern of exploitation was consistent with commercial spyware vendors, the kind that sell surveillance tools to governments, though that is IntoMobile's inference rather than a claim either Google or CISA has made.
The fix requires no workaround: any supported Pixel running the Sept. 5 patch level or later is already protected. Devices that have not installed a security update since early September remain exposed for as long as they stay adjacent to an attacker capable of reaching the modem. CISA's disclosure of the CenterPoint Energy breach earlier this month made a similar point about exposure windows on critical systems, though there the perimeter was a utility's network rather than a phone's radio range. CISA gave the same three-day window to the CVSS 10 Adobe Commerce zero-day it added to the catalog on Sept. 8, which suggests the short clock tracks confirmed exploitation rather than how a bug scores on paper.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.