Google disclosed that a vulnerability in Pixel phones' modem software, tracked as CVE-2026-58704, was exploited in a limited number of targeted attacks before being patched this week. The flaw allowed attackers to escalate privileges from the isolated modem component into the phone's broader system without any user interaction, a so-called zero-click exploit. Google has not identified who carried out the attacks.
techcrunch.com
· 2026-09-16
Google's September 2026 security bulletin fixes 110 vulnerabilities in Pixel devices, including a high-severity flaw (CVE-2026-58704) in the Cellular Modem component that is being exploited in limited, targeted attacks. The bug stems from a logic error that lets an attacker on an adjacent network bypass permissions and escalate privileges without user interaction. The update, rolling out at patch level 2026-09-05, also addresses 12 critical remote code execution bugs and 89 privilege escalation issues.
bleepingcomputer.com
· 2026-09-16
Acronis has patched a high-severity local privilege escalation flaw, tracked as CVE-2026-87886, in its backup add-ons for cPanel/WHM and Plesk. The company says it has seen limited, targeted exploitation attempts against affected deployments, based on a report from one potentially affected customer. Fixed versions are 1.9.3 HF3 for cPanel/WHM and 1.8.11 for Plesk.
bleepingcomputer.com
· 2026-09-15
A researcher going by 'Nightmare Eclipse' released a privilege-escalation exploit dubbed FalconFlank that abuses CrowdStrike Falcon's malicious macro remediation feature to gain SYSTEM-level command prompt access on fully patched Windows 11 25H2 and Windows Server 2025 machines. The flaw has no CVE yet, and CrowdStrike says it is investigating while telling customers to disable the Office File Suspicious Macro Removal policy setting as a workaround.
bleepingcomputer.com
· 2026-09-04
ServiceNow issued fixes for three critical vulnerabilities in its AI Platform that could let unauthenticated attackers run arbitrary code, escalate privileges, or manipulate data via SQL injection, all without user interaction. The company also patched a separate high-severity sandbox escape bug that could allow low-privileged users to achieve remote code execution. ServiceNow says it has no evidence of active exploitation but is urging customers to apply the updates immediately.
bleepingcomputer.com
· 2026-08-28