What Is the September 2026 Android Security Update? 180 Vulnerabilities Explained

2026-09-29
The September 2026 Android security update fixes 180 vulnerabilities, including a critical RCE flaw. Here's what the Android Security Bulletin means for you.
The September 2026 Android security update patches 180 vulnerabilities, and the headline number matters less than one detail buried in the bulletin: the most severe flaw is a critical remote code execution bug in the System component that needs no user interaction to exploit. In plain terms, an attacker could potentially run code on your device without you tapping anything.
That's the kind of finding that turns a routine monthly security update into a push-your-update-now situation. This guide explains what the Android Security Bulletin actually is, what this month's patch fixes, and why this one stands out from the summer's quiet releases.
What the Android Security Bulletin Is
Every month, Google publishes a document called the Android Security Bulletin. It lists the security vulnerabilities fixed in that month's patch, grouped by the component they affect, along with each flaw's CVE ID, severity rating, and the Android versions it applies to.
The bulletin isn't a consumer document. It's written for device manufacturers and carriers so they know what to fix in their own builds. But it's public, and reading it tells you exactly how serious a given month's update is. When a bulletin names a "critical" severity flaw, take it seriously. Critical, in Google's rating system, means the vulnerability can be exploited remotely with little effort.
Android updates roll out in waves because Google builds the patch, but each manufacturer has to adapt it for their phones. That's the gap that frustrates people: Google fixes a bug in September, and your Samsung or Pixel or Motorola might not see it until weeks later. The bulletin tells you what's fixed, not when your phone gets it.
What the September 2026 Patch Fixes
Google shipped September's fixes in two parts, and together they cover the 180 vulnerabilities in this month's Android security update.
The first release, dated 2026-09-01, addresses 95 flaws. It covers Android Runtime, Framework, System, Setup Wizard, and several Project Mainline modules delivered through Google Play system updates. Breaking it down: 56 fixes in the System component, 23 of them rated critical, plus 37 fixes in Framework including three critical bugs, and one fix in Android Runtime.
The second, dated 2026-09-05, adds 85 more fixes focused on the Android kernel and vendor-supplied code. It covers components from Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc, and Qualcomm, along with platform code used by TV devices.
If your device reports a security patch level of 2026-09-05 or later, you have both releases. There were no separate bulletins for Wear OS, Android XR, or Android Automotive OS this month; updates for those platforms address the same issues.
Why the Critical RCE Flaw Matters
The standout vulnerability is a critical remote code execution flaw in the System component. Google's bulletin spells out the risk precisely: remote code execution with no additional execution privileges needed, and no user interaction required for exploitation.
Those two phrases are what make it serious. Many Android flaws require an attacker to already have some foothold, or require you to click a malicious link. This one needs neither special privileges nor a tap from you. Security researchers also flagged CVE-2026-28662, a Wi-Fi-related memory corruption flaw that could let an attacker execute code remotely and escalate privileges, again without user interaction.
The Wi-Fi angle is the part that should raise eyebrows for anyone curious about why this month got attention. A flaw reachable over Wi-Fi means an attacker on the same network or within radio range could be a potential entry point, which is a broader threat surface than a bug that needs a specific app or a lure.
Why This Month Stands Out
Here's a contrast worth knowing. July and August 2026 contained no Android security vulnerability bulletins at all. Google published nothing for those two months, an unusually quiet stretch, which is why the September release reads as dramatic by comparison.
The jump from zero published bulletins to 180 fixed flaws isn't necessarily a security crisis. Patch cadence varies, and Google sometimes batches fixes. But it does mean September 2026 is the first substantial Android security update in months, and the critical RCE finding gives it more weight than a routine roll-up.
For anyone who let their device lag over the summer, this is the month to catch up, because the fixes you skipped are now stacked on top of September's.
Android September Patch: What You Should Do
The action here is simple, even if the rollout isn't instant.
1. Open Settings on your Android phone.
2. Go to About phone or System, then Software update or Security.
3. Check your security patch level.
4. If it shows anything earlier than 2026-09-05, tap to check for updates and install any pending ones.
If your device is a Pixel, you'll typically see the patch quickly. Other manufacturers vary, and some budget phones stop receiving updates entirely after a few years. If your phone no longer gets security patches, that's a real limitation to weigh, not just a marketing detail.
Why Monthly Patches Are Worth Reading
Most people ignore the "update available" prompt until it becomes annoying, and that habit is exactly what a critical flaw exploits. The Android Security Bulletin exists so you can tell a routine month from a serious one. When a bulletin names a vulnerability "critical" and notes that no user interaction is needed, it's telling you the bug doesn't wait for you to make a mistake. Waiting to patch helps no one but an attacker.
The counterargument is that most Android flaws never get exploited in the wild, and that's often true. But "often" is doing a lot of work in that sentence, and the cost of updating is a few minutes and a Wi-Fi connection. The cost of a successful remote code execution exploit is far higher, which is why security researchers urged organizations to push the September update across device fleets quickly.
There's also a bigger picture worth knowing: Google's Project Mainline modules ship through Google Play system updates, which means some of this month's fixes reach your phone without your manufacturer's involvement. That's a quiet improvement in how Android handles security, even if it doesn't cover every component.
The Takeaway on the Android Security Update September 2026
The September 2026 Android security update is the most consequential in months, not because the sky is falling but because a critical, no-tap-required RCE flaw sits at the top of the list and the summer was otherwise silent. The Android Security Bulletin exists so you can see that difference, and this month the difference is real.
Check your patch level, install what's waiting, and don't dismiss the update prompt. The 180 vulnerabilities will be fixed whenever your manufacturer pushes the build, and until then you're running code with known holes. If you want to confirm what's covered, Google's AOSP bulletin page is publicly readable and lists every CVE. Update your device, keep Play Protect on, and treat the critical rating for what it represents: a reason to act now rather than later.