Samsung Ships Largest Single-Month Security Patch of 2026
Samsung has released its July 2026 Security Maintenance Release (SMR), delivering patches for a record-breaking 57 security vulnerabilities across the Galaxy device ecosystem. This update incorporates 41 patches sourced directly from Google’s July 2026 Android Security Bulletin, alongside 16 additional Samsung-specific CVE fixes targeting proprietary Galaxy software components including Knox Workspace, SmartThings, Samsung Internet browser, and the Samsung Camera processing subsystem. Here is a full breakdown of what is patched and which Galaxy devices are receiving the critical update.
Vulnerability Severity Breakdown
Of the 57 total vulnerabilities addressed in this month’s maintenance release, the severity distribution across the Samsung ecosystem is:
- 5 Critical-Severity Vulnerabilities: The highest-risk class, where exploitation can lead to full remote code execution, complete device compromise, or permanent data destruction without requiring any user interaction or unlocked device access.
- 42 High-Severity Vulnerabilities: Significant flaws affecting Bluetooth stack parsing logic, Samsung Internet browser rendering engine, NFC card emulation modules, and Samsung Pay transaction validation layers used in contactless payments.
- 10 Moderate-Severity Vulnerabilities: Lower-risk issues including local privilege escalation bugs in Samsung Pay and permission bypass flaws in Bixby Voice routines and third-party app integrations.
Critical Flaws: Remote Code Execution via Media Processing
Among the five critical-severity vulnerabilities, two are particularly notable for their zero-interaction exploitation potential:
- CVE-2026-32781 (Samsung Video Decoder): A heap-overflow bug in Samsung’s proprietary video decoder library allowed attackers to execute arbitrary code by sending a specially crafted malicious video file via MMS or WhatsApp to a vulnerable Galaxy device—requiring no additional user permission or active device interaction.
- CVE-2026-31045 (SmartThings Hub): An authentication bypass in the SmartThings Hub local API allowed unauthorized devices on the same Wi-Fi network to issue commands to connected smart home peripherals without password verification.
Eligible Galaxy Devices Receiving the July Patch
Samsung’s July 2026 SMR is rolling out in staged regional waves to the following device families:
- Galaxy S Series: Galaxy S26, S25, S24, S23, S22 Ultra, and S21 FE
- Galaxy A Series: Galaxy A56, A36, A26, A16, and A06
- Galaxy Z Series: Galaxy Z Fold 8, Z Fold 7, Z Flip 8, and Z Flip 7
- Galaxy Tab Series: Galaxy Tab S10 Ultra, Tab S9+, and Tab A9+
How to Check and Install the July 2026 Update
Navigate to Settings > Software update > Download and install to receive the latest patch. Security analysts strongly recommend applying this update immediately given the presence of critical remote-code-execution vulnerabilities in media processing. For ongoing Samsung security news, patch notes, and Galaxy vulnerability breakdowns, visit Android People.