Pixel Modem Zero-Day Exploited in Targeted Attacks

2026-09-16T13:24:00Z•f101492e04ba5d41a646044f48b9e6602b2683ce6ceab7c0bca3f99ff0737050
CVE-2026-5430CVE-2026-58704CVE-2026-87886AI-privacyAcronisAndroidChromeFirefoxGoogle PixelIranOracleTelegram C2The Events CalendarWSO2WordPresscPanelexploitation-in-the-wildhealthcare-data-breachprivilege-escalationremote-code-executionsurveillance-malwarevulnerability-managementzero-day

What happened

SecurityWeek reports multiple significant cybersecurity developments, including an exploited Google Pixel modem privilege-escalation zero-day (CVE-2026-58704), an exploited Acronis cPanel backup plugin privilege-escalation flaw (CVE-2026-87886), attacks targeting a WSO2 vulnerability (CVE-2026-5430), unauthenticated remote-code-execution vulnerabilities in The Events Calendar WordPress plugin affecting more than 200,000 sites, and broad security updates from Oracle, Chrome, and Firefox. The feed also covers Iranian surveillance malware, a healthcare data breach affecting approximately 280,000-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
f101492e04ba5d41a646044f48b9e6602b2683ce6ceab7c0bca3f99ff0737050
Enrichment time
2026-09-16T13:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.