Samsung has started rolling out its October 2026 security update to some of its newest Galaxy phones, including its latest foldables.
The monthly Security Maintenance Release combines Google Android patches with fixes for Samsung-specific vulnerabilities. Samsung’s bulletin lists nine critical Google vulnerabilities, along with 33 high- and three moderate-severity flaws.
Samsung also addressed four high-severity vulnerabilities affecting Samsung Semiconductor products. Among the Galaxy phones already receiving the update are the Galaxy S26, S26 Plus, S26 Ultra, S26 FE, Z Fold 8, Z Fold 8 Ultra and Z Flip 8.
Latest Galaxy foldables get the patch first
Samsung has specifically started rolling out the October patch to its latest foldables in South Korea, according to SamMobile. The Galaxy Z Fold 8 Ultra update is listed at 5,298.47MB and carries firmware version F976NKSS3AZIJ.
SamMobile reports that the Galaxy Z Fold 8 and Z Flip 8 updates should have similar package sizes and firmware versions ending in AZIJ. The rollout is expected to expand to additional markets gradually. Samsung typically releases its monthly updates in stages, so availability can vary by country, model and carrier.
What Samsung fixed
The Samsung-specific portion of the update addresses vulnerabilities affecting Android 14 through Android 17, including several flaws that could potentially lead to arbitrary code execution.
One high-severity issue in libsmkvextractor.so, for example, could allow a local attacker to execute arbitrary code because of an out-of-bounds write. Another flaw in the WSM service could potentially provide system-level code execution through a use-after-free vulnerability.
Samsung also fixed issues involving image processing, Samsung's text-to-speech software, Locksettings and access controls. The company says some Samsung Vulnerabilities and Exposures (SVE) items in the October release cannot yet be disclosed.
Why this patch is more than routine maintenance
The true significance of Samsung's October patch lies beyond the raw count of resolved flaws. Several of the disclosed Samsung flaws affect low-level components that sit close to core system functions, meaning successful exploitation could have consequences beyond a single application.
At the same time, Samsung describes the affected vulnerabilities as requiring local attackers in the disclosed cases. That reduces the likelihood of casual remote exploitation but does not make the flaws irrelevant, particularly on devices containing sensitive personal and business data.
For organizations managing Galaxy devices, the main issue is coverage. A phased rollout means different users may receive the same monthly security patch at different times depending on device, carrier and region.
What Galaxy users should do
If the October update is available, installing it promptly is the sensible move. Samsung recommends checking Settings > Software update > Download and install.
Users whose phones have not received the patch yet do not necessarily have a problem. Samsung is rolling it out progressively, and availability can depend on the device, market and carrier.
Businesses managing Galaxy fleets should verify patch levels across enrolled devices rather than assuming the October SMR has reached every handset at the same time. That is especially important for organizations allowing Galaxy devices to access corporate email, credentials or internal applications.
Other news: Attackers are probing CVE-2026-61500, a critical Rejetto HFS flaw that can let unauthenticated attackers forge administrator sessions and achieve remote code execution.





