CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added CVE-2026-58704, a Google Pixel Improper Authorization Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action reinforces Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets.

IFF Assessment

FOE

The article details a newly identified actively exploited vulnerability, which represents a direct threat to systems and requires immediate attention from defenders.

Severity

8.0 High

CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of CVE-2026-58704, especially if managing Google Pixel devices or related infrastructure, and prioritize patching as it has been identified as actively exploited. This highlights the importance of continuously monitoring CISA's KEV Catalog for vulnerabilities that pose immediate risks and require rapid remediation.

Read Full Story →