Google Pixel CVE-2026-58704: Modem Improper Auth — KEV Due September 19

By George Bailey   Published: 09/16/26   Updated: 09/16/26   2 min read

Yesterday’s newest KEV entry is sitting in people’s pockets. CISA added an actively exploited Google Pixel improper-authorization flaw in the cellular modem — with a federal due date of September 19, 2026.

If executives, admins, or field staff carry corporate or BYOD Pixels into email, VPN, and MFA, this is a fleet compliance event, not a consumer footnote.

What happened

On September 16, 2026, CISA announced one new Known Exploited Vulnerability: CVE-2026-58704, described as a Google Pixel improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges on affected devices.

CISA’s remediation due date is September 19, 2026. Forensic triage is required per BOD 26-04. The agency points defenders at Google’s September Pixel security bulletin for the fixed security patch level.

Why it matters

Mobile authorization bypasses rarely stay “just phone problems.” They sit under the apps that hold SSO sessions, authenticator tokens, corporate mail, and VPN profiles.

KEV inclusion means exploitation evidence cleared CISA’s bar. Waiting for a perfect CVSS write-up is how fleets miss a three-day federal clock.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.