Google’s September Pixel update fixes CVE-2026-58704, a high-severity cellular-modem privilege escalation (CVSS roughly 8.0–8.8) that can enable a zero-click / adjacent-remote permission bypass. Google says exploitation was limited and targeted. The fix lands in the 2026-09-05 patch level — push Pixel fleets (especially exec/BYOD) the same day you would push a critical MDM app update. Modem code sits below typical app-layer MDM controls.

Also Sep 16: Acronis patched an insecure file-permissions bug in its Backup cPanel/WHM plugin (CVE-2026-87886, CVSS 7.8 local privilege escalation). Limited targeted attacks were reported on the cPanel/WHM plugin (not on Plesk). Affected: cPanel/WHM before 1.9.3.1021; Plesk before 1.8.11.638. CISA added it to KEV the same day.

If you host or manage cPanel for clients, upgrade the plugin and assume compromise until proven otherwise — backup tooling sits on the ransomware recovery path. For Pixel users in the tenant, treat “OS patch level” as a security control, not a consumer chore.