Samsung has published the details of its June 2026 Security Maintenance Release (SMR) for its extensive lineup of Galaxy smartphones, tablets, and foldable devices. The update addresses a total of 45 security vulnerabilities. This package includes fixes for Common Vulnerabilities and Exposures (CVEs) identified in Google's June 2026 Android Security Bulletin, as well as 11 fixes for Samsung Vulnerabilities and Exposures (SVEs), which are specific to Samsung's own software and hardware. The update is critical for maintaining the security and stability of Galaxy devices. The rollout will occur in stages over the coming weeks, and users are strongly encouraged to apply the update promptly.
The June 2026 SMR is a comprehensive update that bundles numerous security enhancements.
The update will be rolled out to all eligible Samsung Galaxy devices that are currently supported with monthly or quarterly security updates. This includes:
The rollout is staggered by device model and carrier. Flagship and unlocked devices typically receive updates first.
Applying this security patch is crucial for protecting user data and device integrity. Unpatched vulnerabilities could potentially be exploited by malicious applications or remote attackers to:
Given that the underlying Google bulletin includes a patch for an actively exploited zero-day, the urgency of this update is high.
Users and enterprise administrators should prioritize the deployment of this patch as follows:
Enterprises using Samsung devices should leverage their Mobile Device Management (MDM) or Enterprise Mobility Management (EMM) solution to enforce the update across their fleet.
For most users, the update process is straightforward:
The following indicators can help identify unpatched or at-risk systems in an enterprise environment:
Android security patch level is not 2026-06-01 or laterMDM/EMM Compliance ReportsSamsung Knox AttestationApplying the monthly security update is the only way to remediate the vulnerabilities addressed in the SMR.
The core defensive action is to ensure the timely deployment of the June 2026 Security Maintenance Release. For enterprises, this means using their Mobile Device Management (MDM) platform to push the update to all managed Samsung Galaxy devices. Compliance policies should be established to track the update's progress and flag devices that have not been patched within a specified timeframe. For individual users, enabling automatic updates is highly recommended. This patch directly addresses 45 security flaws, and applying it is the most effective way to protect the device from these specific threats.
Samsung officially details the contents of its June 2026 Security Maintenance Release.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.