Samsung Releases October 2026 Security Patch: Full List of Fixes and Devices

Samsung’s October 2026 security update fixes critical and high-severity Android and Galaxy flaws, with rollout beginning on newer flagship devices.

Oct 6, 2026
3 minute read
black sony remote control beside white tissue paper

Samsung October 2026 patch tackles critical Android and Galaxy security flaws. Image: Anh Nhat/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Samsung has started rolling out its October 2026 security update to some of its newest Galaxy phones, including its latest foldables.

The monthly Security Maintenance Release combines Google Android patches with fixes for Samsung-specific vulnerabilities. Samsung’s bulletin lists nine critical Google vulnerabilities, along with 33 high- and three moderate-severity flaws.

Samsung also addressed four high-severity vulnerabilities affecting Samsung Semiconductor products. Among the Galaxy phones already receiving the update are the Galaxy S26, S26 Plus, S26 Ultra, S26 FE, Z Fold 8, Z Fold 8 Ultra and Z Flip 8.

Latest Galaxy foldables get the patch first

Samsung has specifically started rolling out the October patch to its latest foldables in South Korea, according to SamMobile. The Galaxy Z Fold 8 Ultra update is listed at 5,298.47MB and carries firmware version F976NKSS3AZIJ. 

SamMobile reports that the Galaxy Z Fold 8 and Z Flip 8 updates should have similar package sizes and firmware versions ending in AZIJ. The rollout is expected to expand to additional markets gradually. Samsung typically releases its monthly updates in stages, so availability can vary by country, model and carrier.

What Samsung fixed

The Samsung-specific portion of the update addresses vulnerabilities affecting Android 14 through Android 17, including several flaws that could potentially lead to arbitrary code execution.

One high-severity issue in libsmkvextractor.so, for example, could allow a local attacker to execute arbitrary code because of an out-of-bounds write. Another flaw in the WSM service could potentially provide system-level code execution through a use-after-free vulnerability.

Samsung also fixed issues involving image processing, Samsung's text-to-speech software, Locksettings and access controls. The company says some Samsung Vulnerabilities and Exposures (SVE) items in the October release cannot yet be disclosed.

Advertisement

Why this patch is more than routine maintenance

The true significance of Samsung's October patch lies beyond the raw count of resolved flaws. Several of the disclosed Samsung flaws affect low-level components that sit close to core system functions, meaning successful exploitation could have consequences beyond a single application.

At the same time, Samsung describes the affected vulnerabilities as requiring local attackers in the disclosed cases. That reduces the likelihood of casual remote exploitation but does not make the flaws irrelevant, particularly on devices containing sensitive personal and business data.

For organizations managing Galaxy devices, the main issue is coverage. A phased rollout means different users may receive the same monthly security patch at different times depending on device, carrier and region.

What Galaxy users should do

If the October update is available, installing it promptly is the sensible move. Samsung recommends checking Settings > Software update > Download and install.

Users whose phones have not received the patch yet do not necessarily have a problem. Samsung is rolling it out progressively, and availability can depend on the device, market and carrier. 

Businesses managing Galaxy fleets should verify patch levels across enrolled devices rather than assuming the October SMR has reached every handset at the same time. That is especially important for organizations allowing Galaxy devices to access corporate email, credentials or internal applications.

Other news: Attackers are probing CVE-2026-61500, a critical Rejetto HFS flaw that can let unauthenticated attackers forge administrator sessions and achieve remote code execution.


Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.