# CISA orders federal agencies to patch exploited Pixel modem zero-day in three days

_Published Thursday, September 17, 2026 at 6:19 PM EDT · Security · Latest · Tier 2 — Notable_

![CISA orders federal agencies to patch exploited Pixel modem zero-day in three days — Primary](https://assets.techrepublic.com/uploads/2026/09/triyansh-gill-zsBPSaTbF5E-unsplash-1.jpg?f=jpeg)

Google disclosed that attackers actively exploited CVE-2026-58704, a high-severity flaw in the cellular modem of Pixel smartphones, before a fix was available.

The defect allows an adjacent attacker to escalate privileges without any user interaction, such as clicking a link or answering a call. Google said in its September Pixel security bulletin that there are indications the flaw may have been under limited, targeted exploitation. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and directed affected federal agencies to remediate within three days.

Google patched the flaw in its September 2026 Pixel security release alongside more than 100 other device-specific fixes.

## Sources

- [TechRepublic](https://www.techrepublic.com/article/news-google-pixel-modem-zero-day-cve-2026-58704/)

---
Canonical: https://techandbusiness.org/newswire/RdAjhDQLZHGzw1Yg8ELhxZ
Published: 2026-09-17T22:19:00.765Z
Story chronology: 2026-09-17T18:46:02.000Z
Retrieved: 2026-09-19T02:05:01.677Z
Publisher: Tech & Business (techandbusiness.org)
