Android September 2026 Security Update Fixes 180 Vulnerabilities Including Critical Remote Code Execution Flaws Across Supported Devices

Android September 2026 security update fixes 180 vulnerabilities, including critical remote code execution flaws, Wi-Fi issues and serious security bugs affecting supported devices.

Android September 2026 Security Update Fixes 180 Vulnerabilities Including Critical Remote Code Execution Flaws Across Supported Devices

Google has released its September 2026 Android security update, addressing 180 vulnerabilities across the Android operating system. Some of the flaws are rated critical and could allow attackers to execute malicious code remotely without requiring any action from the user.

The Android security update is being delivered through two security patch levels. The September 1 patch addresses 95 vulnerabilities affecting Android Runtime, Framework, System, Setup Wizard and several Project Mainline components. The September 5 patch adds another 85 fixes covering the Linux kernel, Android TV and various hardware-related components.

Google said the most serious vulnerability affects the Android System component and could allow remote code execution without requiring additional permissions or user interaction. The September 1 update includes 56 fixes for the System component, including 23 critical-severity vulnerabilities. The Android Framework has 37 fixes, while Android Runtime has one.

Google has also listed several other critical vulnerabilities, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639 and CVE-2026-28662. The latter affects the Android Wi-Fi system.

The update also addresses serious vulnerabilities in the Linux kernel, including issues involving NFC and Protected Kernel-Based Virtual Machine components. Additional fixes cover hardware components from Arm, MediaTek, Qualcomm, Unisoc and Imagination Technologies.

Samsung has also rolled out its September 2026 security update for Galaxy devices. The company has addressed 18 critical and 40 high-severity vulnerabilities identified by Google, along with 31 Samsung-specific security issues. Two critical vulnerabilities, CVE-2026-21095 and CVE-2026-21096, affect Samsung's image codec library and its DNG and JPG decoders.

The availability of the Samsung security update varies depending on the Galaxy model and region. Some flagship devices receive security updates every month, while other models are covered by quarterly update schedules.

Google recommends installing the latest Android security patch as soon as it becomes available. A device showing the September 5, 2026 security patch level or later includes the applicable September security fixes.

Users can check their security patch date under Settings > Security and privacy > System and updates, although the exact menu path may vary depending on the phone manufacturer. It is also important to remember that devices that have reached the end of their manufacturer's support period may no longer receive security updates.

Google Play Protect can help detect harmful applications, but it cannot fix vulnerabilities in Android itself, the Linux kernel or a device's hardware. Keeping the operating system and apps updated therefore remains an important part of protecting an Android device.

Information referenced in this article is from Tech Republic