ximitime.com Xiaomi September 2026 Security Update Addresses Critical Vulnerabilities
Article Content
- •Xiaomi's September 2026 update fixes 180 vulnerabilities, including critical RCE flaws.
- •Affected devices include flagship Xiaomi, POCO, and Redmi models, primarily in China.
- •Users are advised to install the update promptly to protect against potential exploits.
Xiaomi has initiated the rollout of its September 2026 Android security patch, addressing critical vulnerabilities across its devices, particularly in the Android framework and system architecture. This update is part of the HyperOS 4 release and primarily targets devices in China, with some global models included. Key vulnerabilities fixed include multiple Remote Code Execution (RCE) flaws (CVE-2026-28604, CVE-2026-28618, CVE-2026-28639) that could allow attackers to execute malicious code without user interaction. The update also addresses Elevation of Privilege (EoP) vulnerabilities (CVE-2026-28666, CVE-2026-55273) that could enable unauthorized access to private data. A total of 180 vulnerabilities are patched, with 95 affecting the core system and framework. Users are urged to install the update as soon as it becomes available to mitigate these risks. The rollout is expected to expand to more devices running older HyperOS versions soon.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-0001 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…