# Global cybersecurity vulnerabilities and exploits

> Live situation record from CLSTR: https://clstr.news/situations/global-cybersecurity-vulnerabilities-and-exploits
> Updated: 2026-09-16T11:15:00.000Z. Sources: 24. Developments: 2.

Global cybersecurity reports indicate a rise in critical vulnerabilities, including significant zero-day exploits and emerging risks associated with artificial intelligence. Major technology companies such as Google, Microsoft, Cisco, and Adobe have faced security challenges, with Microsoft reporting nearly 1,000 CVEs in a single update cycle.

Specific threats include the exploitation of Chrome zero-days and vulnerabilities in AI supply chains. A significant focus has been placed on CVE-2026-58704, a high-severity zero-click modem flaw in Google Pixel smartphones. This vulnerability allows attackers in close proximity to bypass security sandboxes and escalate privileges without user interaction. Google has indicated the flaw may be subject to limited, targeted exploitation.

In response to the modem flaw, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated that federal agencies patch the flaw within three days. Google has since released its September 2026 Pixel security update and the stable rollout of Android 17 QPR1 to address 110 vulnerabilities across components including the bootloader, Bluetooth, and graphics.

## Claims

- The vulnerability CVE-2026-58704 may be under limited, targeted exploitation. (corroborated by 17 sources)
- The CVE-2026-58704 vulnerability is a high-severity privilege escalation flaw located in the cellular modem. (corroborated by 14 sources)
- The modem vulnerability can be exploited without any user interaction. (corroborated by 13 sources)
- The Pixel Drop includes new Scam Detection features for Gboard and Messages. (corroborated by 5 sources)
- The September 2026 Pixel update addresses 110 vulnerabilities. (corroborated by 4 sources)
- The September update includes Android 17 QPR1 for Pixel devices. (corroborated by 3 sources)

## Timeline

### 2026-09-16: Google Pixel updates address exploited modem flaw and Android 17 QPR1

Google has patched a high-severity, zero-click modem vulnerability (CVE-2026-58704) in Pixel smartphones that is reportedly under targeted exploitation. The update also includes Android 17 QPR1 and new Pixel-up

23 sources. https://clstr.news/cluster/google-patches-pixel-modem-flaw-amid-signs-of-targeted-exploitation

### 2026-09-13: Global cybersecurity report highlights major zero-day exploits and AI risks

A cybersecurity report details widespread threats, including multiple zero-day exploits in Google and Microsoft software, AI supply chain vulnerabilities, and significant data breaches affecting millions of-us-

2 sources. https://clstr.news/cluster/global-cybersecurity-report-highlights-major-zero-day-exploits-and-ai-risks

---
Cite as: Global cybersecurity vulnerabilities and exploits. CLSTR, https://clstr.news/situations/global-cybersecurity-vulnerabilities-and-exploits
