Google fixes actively exploited Android zero-day on Pixel devices

2026-09-16T07:23:20Z•3239e6d93dedf3215b9fa4e087dd89fb85d3a7654ba1b4e48192a63ac407c644
AcronisAndroidBambooTokenCisco Secure Email GatewayLinuxMQTTOAuth token theftPHP backdoorPixelPleskVMware vCenterWHMWindowsWooCommerceWordPressactive exploitationcPanelcybercrimedata breachransomwaresupply-chain compromisevulnerability remediationzero-day

What happened

A BleepingComputer security news digest covering multiple active threats and vulnerabilities, including exploited Android, Cisco Secure Email Gateway, VMware vCenter, Acronis backup plugin, and WordPress plugin flaws; malware using MQTT to control Windows and Linux systems; supply-chain compromise of a WordPress plugin; data breaches; exposed OAuth tokens; and cybercrime activity. Several items involve active exploitation, remote code execution, privilege escalation, backdoors, or ransomware operations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3239e6d93dedf3215b9fa4e087dd89fb85d3a7654ba1b4e48192a63ac407c644
Enrichment time
2026-09-16T07:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google fixes actively exploited Android zero-day on Pixel devices · Baitaphish