← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.00

Google fixes actively exploited Android zero-day on Pixel devices

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]

7 zpráv z 7 zdrojů · první 16. 9. 02:00 · poslední 17. 9. 04:00 CZ · EN/orig

Google veřejná správa FI US IT FR

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-58704 8.0 3.1 · CISA-ADP KEV ✓ 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Dalších 1 CVE zmiňuje jen text zpravodajského článku (CVE-2025-48595). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 7

  1. · NCSC-FI FI

    Pixel Update Bulletin—September 2026

    Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-56914, CVE-2026-58773, CVE-2026-55318, CVE-2026-55343, CVE-2026-56920, CVE-2026-56967, CVE-2026-58683, CVE-2026-58710, CVE-2026-0179, CVE-2026-0187, CVE-2026-0192, CVE-2026-0194, CVE-2026-0199, CVE-2026-0200, CVE-2026-55302, CVE-2026-55317, CVE-2026-55323, CVE-2026-55329, CVE-2026-55337, CVE-2026-55357 (+90 other associated CVEs), Summary: The Pixel Update Bulletin contains details of…

  2. · CISA Advisories US

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

  3. · Malwarebytes Labs US

    Google Pixel owners urged to patch actively exploited modem flaw

    Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.” The bug is not described as a simple remote takeover, but as a vulnerability that could give an attacker who already has a foothold on a phone more power than they should have. Although Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches distributed to Android…

  4. · CSIRT Itálie (ACN) IT

    Aggiornamenti di sicurezza per dispositivi Google Pixel

    Aggiornamenti di sicurezza Google di settembre risolvono molteplici vulnerabilità, di cui 46 con gravità “critica” e 63 con gravità “alta”, nei dispositivi Pixel.

  5. · BleepingComputer US nadpis události

    Google fixes actively exploited Android zero-day on Pixel devices

    Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]

  6. · CISA KEV US

    Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)

    CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities catalog. Affected product: Google Pixel. Remediation due date: 2026-09-19.

  7. · CERT-FR – avis FR

    Multiples vulnérabilités dans Google Pixel (16 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Google Pixel. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données. Google indique que la vulnérabilité...