Search
Find merged stories by title or summary.
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added [ 1 , 2 ] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-76460 (CVSS score of 10.0) Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability • CVE-2026-87886 (CVSS score NA) Acronis Backup Incorrect Default Permissions Vulnerability • CVE-2026-58704 (CVSS score of 8.8) Google Pixel Improper Authorization Vulnerability CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw is caused by inadequate authentication checks on a specific API endpoint.
Google patches Pixel modem zero-day exploited in targeted attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has already been exploited in the wild. “In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the advisory . The vulnerability is an elevation-of-privilege issue caused by a permission bypass resulting from a logic error in the modem code.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
[Previdian] CVE-2026-58704 - Confirmed Exploitation
CVE-2026-58704 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-16 08:15 UTC Evidence Sources: 1 First Seen: 2026-09-16 Asserted: 2026-09-16
NVD-CVE-2026-58704 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-58704 National Institute of Standards and Technology (.gov)
You've reached the end of current stories for this search.
