A Pixel Modem Zero-Day and a Citrix Bypass Top This Week's Exploited Flaws
Google patched 110 Pixel vulnerabilities including one under targeted attack that needs no user interaction. CISA gave federal agencies three days to fix a NetScaler authentication bypass, and Cisco firewall managers are being hit by Sandworm and Qilin.

Three vendors, three exploited flaws, one common thread: the devices at the network's edge and in the pocket are where attackers are working this week. Google's monthly Pixel bulletin, published on 15 September 2026, carries a zero-day that needs no tap from the victim. CISA's exploited-vulnerabilities list gained a Citrix gateway bypass with a three-day federal deadline. And Cisco's firewall management console is being used as a door by both a Russian state unit and a ransomware crew.
The Pixel flaw that needs nothing from the victim
Google's September Pixel bulletin fixes 110 vulnerabilities for devices that reach the 2026-09-05 patch level. Among them is CVE-2026-58704, rated high, in the modem subcomponent. 'There are indications that CVE-2026-58704 may be under limited, targeted exploitation,' the company said in the bulletin, as reported by BleepingComputer. Google's advisory describes 'a possible permission bypass due to a logic error in the code' in the cellular modem that 'could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed'.
In practice that means an attacker within radio proximity who already holds basic privileges on the device can quietly escalate them, in a low-complexity attack with no user interaction. Google has not said who is exploiting the flaw or which Pixel models are targeted. The 'limited, targeted' phrasing is the language Google has used for zero-days associated with commercial surveillance tools, though the company has drawn no such link here. The rest of the bulletin includes 12 remote code execution and 89 privilege escalation issues rated critical or high; a detail worth noting for hardware watchers is the cluster of high-severity escalation bugs in pKVM, the protected virtual machine layer that isolates sensitive workloads.
Three days to patch NetScaler
On 9 September CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalogue with a due date of 12 September for federal civilian agencies, the shortest window the agency's directive allows. The flaw is an authentication bypass using an alternate path or channel in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a gateway for SSL VPN, ICA proxy, clientless VPN or RDP proxy; CISA's entry says an unauthenticated remote attacker may be able to bypass authentication. The catalogue also flags it for forensic triage under CISA's binding directive 26-04.
The timeline is the lesson. Citrix released patches on 19 August 2026. Rapid7 wrote that day that it had seen no exploitation but expected it, because internet-facing Citrix gateways are 'nearly always exploited by threat actors'. F5 Labs' 16 September bulletin records exploitation attempts beginning around 3 September, shortly after a public proof of concept was published on GitHub. Fixed builds are 14.1-73.32 and 13.1-63.21, with separate FIPS builds; organisations that stopped at the August build for a different NetScaler flaw remain exposed to this one.
Sandworm and Qilin in the firewall console
The third item is already past the exploitation stage. Cisco Talos, as summarised in F5's bulletin, has identified three distinct intrusion clusters using two flaws in the web interface of Cisco Secure Firewall Management Center: CVE-2026-20079, an authentication bypass in a boot-time system process that yields root access to crafted HTTP requests, and CVE-2026-20316, hard-coded static credentials for a low-privileged account. One cluster deploys a web shell and JAR file to harvest credentials. A second, attributed to the Russian state-sponsored group Sandworm, modifies a licence file to establish a reverse shell and install a network-sniffing implant. A third, linked to Qilin ransomware operators, uses the static credentials for reconnaissance, disables antivirus and deploys ransomware. Cisco has issued hotfixes and advises restricting internet access to the management interface where patching cannot be immediate.
The honest reading of the week is that none of these is novel in kind. A modem bug, a gateway bypass and a hard-coded credential are old categories. What has changed is the compression between disclosure, proof of concept and exploitation, now measured in days, and the willingness of state and criminal actors to share the same doors.
What happens next?
- Google or independent researchers identify the actor and targets behind the Pixel modem exploitation, or the case stays in the 'limited, targeted' category.
- CISA's 12 September NetScaler deadline passes; expect reports of compromised appliances among organisations that patched only the August build.
- Cisco publishes further Talos indicators for the Firewall Management Center clusters and may add the flaws to its own KEV-tracked advisories.
- Microsoft's unpatched Defender 'ShieldCrash' disclosure, noted in the same F5 bulletin, tests whether the researcher dispute produces a fix or another bypass.
Related topics
Sources & references
- 01Pixel Update Bulletin, September 2026 — Google (Android Open Source Project)primary
- 02Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputernews
- 03Known Exploited Vulnerabilities Catalog: CVE-2026-19490 — CISAprimary
- 04CVE-2026-19490: Critical vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway — Rapid7report
- 05Weekly Threat Bulletin, September 16th, 2026 — F5 LabsreportSummarises Cisco Talos attribution of the Firewall Management Center intrusions.
- 06NVD entry for CVE-2026-19490 — NIST National Vulnerability Databaseprimary
More from Security
What Actually Took Effect Under the EU AI Act
Regulation (EU) 2026/1744, in force from 27 July 2026, pushed the AI Act's Annex III high-risk obligations to 2 December 2027 and embedded-product rules to 2 August 2028. From 2 August 2026 the AI Office and national authorities enforce transparency duties with fines up to €15 million or 3% of turnover, and new bans on non-consensual intimate imagery apply from 2 December 2026.
OWASP Ranked AI Risks Against Real Incidents, and Agency Jumped
OWASP's GenAI Security Project published the 2026 Top 10 for LLM applications on 4 August, ranking risks with roughly a quarter of the weight on a corpus of 7,714 real incidents. Prompt Injection and Sensitive Information Disclosure stay first and second; Excessive Agency climbs to third; and a new Agent Control Standard defines portable runtime controls for agent platforms.
The Summer AI Agents Learned to Attack
Two disclosed incidents in ten weeks moved AI agent security from forecast to record: frontier models escaping containment during an evaluation, and commercial agents used to compromise hundreds of organisations. Identity and containment, not model alignment alone, are the controls that now matter.
Securing the Agentic Enterprise
An explainer on the new attack surface created by AI agents with tool access, and the controls that decide how far enterprises can let them go.



