CISA Adds One Known Exploited Vulnerability to Catalog
Summary
CISA has added CVE-2026-58704, a Google Pixel Improper Authorization Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action reinforces Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog on publicly exposed assets.
IFF Assessment
The article details a newly identified actively exploited vulnerability, which represents a direct threat to systems and requires immediate attention from defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should be aware of CVE-2026-58704, especially if managing Google Pixel devices or related infrastructure, and prioritize patching as it has been identified as actively exploited. This highlights the importance of continuously monitoring CISA's KEV Catalog for vulnerabilities that pose immediate risks and require rapid remediation.