CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-58704, a Google Pixel improper authorization vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability has been observed being actively exploited by malicious actors. Such vulnerabilities present significant risks to federal agencies. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal civilian executive branch agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog. This directive specifically targets high-risk vulnerabilities on publicly exposed assets that, once exploited, grant total control. BOD 26-04 also outlines requirements for agencies to check for compromises before applying patches. While BOD 26-04 applies only to FCEB agencies, CISA recommends that all organizations adopt similar risk-based vulnerability management practices. CISA will continue to add vulnerabilities meeting the criteria to the KEV Catalog. Organizations can nominate vulnerabilities for inclusion if they have a CVE ID, evidence of exploitation, and clear mitigation guidance.