Skip to content
Android's September 2026 Updates Patch 180 Vulnerabilities

Android's September 2026 Updates Patch 180 Vulnerabilities

Securityweek September 9, 2026

After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates.

As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates).

“The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory .

The security refresh addresses 56 security defects in the System component, including 23 critical-severity flaws that could lead to remote code execution (RCE), elevation of privilege (EoP), and denial-of-service (DoS).

The update also fixes 37 vulnerabilities in the Framework component, including three critical-severity bugs, and one flaw in Android runtime.

The second part of the update, the 2026-09-05 security patch level , contains fixes for 85 security defects across Android’s kernel and its components, as well as TV, Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc, and Qualcomm components.

Android’s September Bulletin is heavy in volume, containing a range of critical and high-severity patches. It’s worth noting that many of the critical severity updates are located in the System, which is responsible for most of a phone’s core functionality like app operation,” Jamf senior enterprise strategy manager Adam Boynton said.

“Most concerning from this list is CVE-2026-28662 because it’s a Wi-Fi-related memory corruption flaw. If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation. It’s crucial that organizations issue the updates across their device fleet as soon as possible,” Boynton added.

Devices updated to a security patch level of 2026-09-05 or newer contain patches for all these vulnerabilities, as well as for the flaws resolved with the Android patches.

There are no specific security patches for Wear OS, Android XR, and Android Automotive OS this month. Their updates, however, fix all the issues described in the September 2026 Android security bulletin.

Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

Related: Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Related: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities

Related: Critical Remote Code Execution Vulnerability Patched in Android

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Exploit Published for Fresh Cleo Harmony Vulnerability

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Hackers Start Exploiting Critical Langflow Vulnerability

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.