Skip to content
Xiaomi September 2026 Security Update Addresses Critical Vulnerabilities

Xiaomi September 2026 Security Update Addresses Critical Vulnerabilities

First seen 23 Sep 2026, 06:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 07:28 UTC
  • Xiaomi's September 2026 update fixes 180 vulnerabilities, including critical RCE flaws.
  • Affected devices include flagship Xiaomi, POCO, and Redmi models, primarily in China.
  • Users are advised to install the update promptly to protect against potential exploits.

Xiaomi has initiated the rollout of its September 2026 Android security patch, addressing critical vulnerabilities across its devices, particularly in the Android framework and system architecture. This update is part of the HyperOS 4 release and primarily targets devices in China, with some global models included. Key vulnerabilities fixed include multiple Remote Code Execution (RCE) flaws (CVE-2026-28604, CVE-2026-28618, CVE-2026-28639) that could allow attackers to execute malicious code without user interaction. The update also addresses Elevation of Privilege (EoP) vulnerabilities (CVE-2026-28666, CVE-2026-55273) that could enable unauthorized access to private data. A total of 180 vulnerabilities are patched, with 95 affecting the core system and framework. Users are urged to install the update as soon as it becomes available to mitigate these risks. The rollout is expected to expand to more devices running older HyperOS versions soon.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-24
CVE-2026-31629 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
Public exploit for CVE-2026-0001 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-08-04
CVE-2026-25289 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
Multiple CVEs published
CVE-2026-28604, CVE-2026-28618, CVE-2026-28639 published, addressing critical RCE vulnerabilities.
Ximitime
2026-09-08
CVE-2026-58846 published
CVE-2026-58846 published, addressing kernel vulnerabilities affecting Xiaomi devices.
Gizmochina
2026-09-08
CVE-2026-28639 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-28666 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-28618 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-28604 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-55273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track CVE-2026-0001 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed