INCIBE-CERT published alert INCIBE-2026-711 on October 7, 2026, relaying Google’s October Android security bulletin. Google’s bulletin, published October 5, lists 25 vulnerabilities: seven critical and 18 high severity.
What the severity classifications mean
Google classifies the seven critical vulnerabilities as denial of service (DoS) or elevation of privilege (EoP). A DoS flaw can disrupt a service; an EoP flaw can let a process gain privileges it should not have.
Remote code execution (RCE) is a separate classification in this bulletin. Google lists CVE-2026-49878 as a high-severity RCE vulnerability.
Affected Android versions and patch level
INCIBE-CERT lists Android 14, Android 15, Android 16, Android 16 QPR2 and Android 17 among the affected versions. Which versions are affected varies by vulnerability.
Google says security patch level 2026-10-01 or later addresses the issues associated with this bulletin level. To check your phone, find the security patch level in its software information and compare it with 2026-10-01; menu names can vary by manufacturer. INCIBE-CERT also recommends installing available Google Play system updates.