A Pixel bug that needs no click just got a 3 day federal deadline
Future Technology
New article published
Security
A Pixel bug that needs no click just got a 3 day federal deadline
Three days. That is how long CISA gave federal civilian agencies to patch CVE-2026-58704, and the shortness of that window is the most informative detail in the advisory.
Key Takeaways
- CVE-2026-58704 is an improper authorisation flaw in the Pixel cellular modem, CVSS 8.0, and requires no user interaction at all.
- CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September with a 19 September deadline for federal civilian agencies.
- Pixel 6 through Pixel 11, plus the Pixel Tablet and Pixel Fold, are affected. Any security patch level before 2026-09-05 is vulnerable.
You received this because you subscribe to Future Technology.