[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTPII5WOTvSqssWxQGMbxSO8vu12aNvv-eBXG3qDg_1k":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"f7a8bce3-e321-424c-882b-ace44f272924","Android’s September 2026 Updates Patch 180 Vulnerabilities","android-s-september-2026-updates-patch-180-vulnerabilities-21e390","The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.","Google has released its September 2026 Android security updates, patching a total of 180 vulnerabilities. The updates are divided into two patch levels, with the first addressing 95 bugs and the second fixing 85. Notably, several critical vulnerabilities in the System component allow for remote code execution without user interaction, and a Wi-Fi-related memory corruption flaw (CVE-2026-28662) is highlighted as particularly concerning.","Android's September 2026 updates address 180 vulnerabilities, including critical RCE flaws.","After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates). “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory. The security refresh addresses 56 security defects in the System component, including 23 critical-severity flaws that could lead to remote code execution (RCE), elevation of privilege (EoP), and denial-of-service (DoS). The update also fixes 37 vulnerabilities in the Framework component, including three critical-severity bugs, and one flaw in Android runtime. The second part of the update, the 2026-09-05 security patch level, contains fixes for 85 security defects across Android’s kernel and its components, as well as TV, Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc, and Qualcomm components.Advertisement. Scroll to continue reading. “Android’s September Bulletin is heavy in volume, containing a range of critical and high-severity patches. It’s worth noting that many of the critical severity updates are located in the System, which is responsible for most of a phone’s core functionality like app operation,” Jamf senior enterprise strategy manager Adam Boynton said. “Most concerning from this list is CVE-2026-28662 because it’s a Wi-Fi-related memory corruption flaw. If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation. It’s crucial that organizations issue the updates across their device fleet as soon as possible,” Boynton added. Devices updated to a security patch level of 2026-09-05 or newer contain patches for all these vulnerabilities, as well as for the flaws resolved with the previous Android patches. There are no specific security patches for Wear OS, Android XR, and Android Automotive OS this month. Their updates, however, fix all the issues described in the September 2026 Android security bulletin. Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws Related: Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk Related: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities Related: Critical Remote Code Execution Vulnerability Patched in Android Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayHackers Return $263 Million Stolen From Liquid NetworkSAP Patches Critical Extended Passport Processing VulnerabilityMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-central Latest News HelmGuard Raises $7.3 Million for Agentic GRC and SecurityAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsIvanti Patches Critical Flaws Across Enterprise Security Products Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fandroids-september-2026-updates-patch-180-vulnerabilities\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FAndroid-update.jpeg","2026-09-09T16:30:40+00:00","2026-09-09T18:00:09.809943+00:00",8,[18,21,24],{"name":19,"type":20},"Android","product",{"name":22,"type":23},"Google","vendor",{"name":25,"type":26},"Wi-Fi","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,35,40],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46],{"type":47,"value":48,"context":49},"cve","CVE-2026-28662","Wi-Fi-related memory corruption flaw in Android System component."]