September Android patches fix 180 security flaws
Google’s September 2026 Android updates patch 180 vulnerabilities in two releases: 2026-09-01 fixes 95 bugs including a critical System RCE; 2026-09-05 fixes 85 kernel and vendor flaws.
Google released two Android security updates in September 2026 that together fix 180 vulnerabilities. The first update, dated 2026-09-01, addresses 95 flaws. The second, dated 2026-09-05, contains 85 fixes.
The 2026-09-01 patch covers Android Runtime, Framework, System, Setup Wizard and several Project Mainline modules delivered through Google Play system updates. It contains 56 fixes in the System component, 23 of them rated critical; 37 fixes in the Framework, including three critical bugs; and one fix in Android Runtime. Google identified a critical System vulnerability that can allow remote code execution without additional privileges or user interaction.
The 2026-09-05 patch focuses on the Android kernel and code supplied by multiple vendors. It includes fixes for platform and vendor components used by devices and targets TV platforms, Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc and Qualcomm components.
Devices reporting a security patch level of 2026-09-05 or later include the fixes from both September releases. There are no separate security patch releases this month for Wear OS, Android XR or Android Automotive OS; updates for those platforms address the same issues listed in the Android security bulletin.
Adam Boynton, Jamf senior enterprise strategy manager, highlighted CVE-2026-28662 as a Wi-Fi-related memory corruption flaw that could enable remote code execution without user interaction and could be used to escalate privileges. He urged organizations to deploy the updates across their device fleets as soon as possible.
July and August 2026 contained no Android security vulnerability bulletins. Users, IT teams and device maintainers should verify device security patch levels and apply vendor-supplied updates when they become available.








