Samsung’s September Update: Fixes for 90 Security Vulnerabilities on Galaxy Devices

Samsung’s September 2026 security update lists fixes tied to 90 vulnerabilities, including critical Android and Galaxy flaws.

Written By
Ken Underhill
Ken Underhill
Sep 8, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Samsung is starting September with another major security cleanup for Galaxy users.

Samsung’s September 2026 security bulletin lists fixes tied to 90 vulnerabilities across Google, Samsung Semiconductor, and Samsung-specific issues, although Samsung notes that some Galaxy-specific fixes may have already appeared in previous maintenance releases. Samsung says the release is being issued for major flagship models, with availability varying by device and region.

Some of the vulnerabilities carry critical severity ratings and could potentially enable remote code execution, making the latest patch an important update for Galaxy users and organizations managing Samsung devices.

September update tackles critical Android vulnerabilities

The September release incorporates fixes from Google’s Android Security Bulletin, which covers vulnerabilities affecting Android Framework, System components, kernel components, and hardware-related software.

Samsung lists 18 critical and 40 high-severity Google vulnerabilities in its September package. The most severe Android issue could allow remote code execution through the System component without requiring additional execution privileges or user interaction.

Devices running the 2026-09-05 security patch level or later address all vulnerabilities covered by Google’s September Android bulletin.

The release follows another sizable round of fixes last month, when Samsung patched 56 Galaxy vulnerabilities, including eight critical Android flaws.

Samsung patches critical Galaxy image-decoder flaws

Samsung’s own September security bulletin lists 31 Samsung Vulnerabilities and Exposures, or SVEs, along with one high-severity vulnerability affecting Samsung Semiconductor software. Samsung notes that some SVE fixes listed in the bulletin may have already been included in previous maintenance releases.

Two of the most serious Samsung-specific vulnerabilities involve image processing.

CVE-2026-21095 is a critical heap-based buffer overflow affecting DNG image decoding, while CVE-2026-21096 is a critical heap-based buffer overflow involving JPEG decoding. Samsung says both vulnerabilities could allow remote attackers to execute arbitrary code.

Advertisement

The company also patched CVE-2026-21092, a path-traversal vulnerability in ImsService that could allow a remote attacker to create image files with system-server privileges.

Other vulnerabilities affect components including GalaxyDiagnostics, SettingsProvider, SystemUI, PROCA, and DualDAR. Two DualDAR vulnerabilities could allow local privileged attackers to execute arbitrary code with root privileges under certain conditions.

The Galaxy-specific fixes are a reminder that Android security extends beyond Google’s monthly patches. Samsung maintains its own applications, services, and security components, which can introduce vulnerabilities separate from those addressed by Google. 

Samsung recently patched four Smart Switch vulnerabilities that could expose sensitive information or allow nearby attackers to impersonate devices. 

What Galaxy owners should do

The availability of Samsung’s monthly security updates can vary by Galaxy model and region.

Users can check for an available update by going to:

Settings → Software update → Download and install

Galaxy owners should install the September security update when it becomes available for their device and confirm that their phone remains within Samsung’s supported update lifecycle.

Organizations should use mobile device management or unified endpoint management system tools to track security patch levels on Galaxy devices that access corporate accounts or sensitive data. 

Mobile threats continue to target Android devices through avenues beyond operating-system vulnerabilities. The recently discovered Manic Android malware, for example, can steal credentials and other sensitive information and use nearby compromised phones to relay the stolen data.

Samsung’s September bulletin does not indicate that the highlighted Samsung-specific vulnerabilities are being actively exploited. Even so, organizations should keep supported Galaxy devices up to date to address both Android- and Samsung-specific security flaws. 

Advertisement

Also read: For another reminder of why mobile security updates matter, read how Google patched an Android zero-day already under active exploitation.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.