Google has launched a major security update, fixing 129 vulnerabilities in the March 2026 Android Security Bulletin. This update is crucial due to reports that attackers are exploiting a high-severity flaw.
The centerpiece of this month’s alert is CVE-2026-21385, a high-severity memory corruption vulnerability affecting a Qualcomm display component. Google has confirmed there are indications this flaw “may be under limited, targeted exploitation”.
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
The issue arises from poor memory allocation alignments. It affects 234 chipsets, including the Snapdragon 8 Elite, various 5G platforms, and automotive parts. This vulnerability is critical as it allows attackers to compromise device integrity.
The 2026-03-01 patch includes key Android updates and addresses 63 vulnerabilities, with two deemed Critical.
System Component (CVE-2026-0006): The update has a serious issue: a Remote Code Execution (RCE) vulnerability. An attacker could potentially control a device remotely without needing extra permissions or user interaction.
Framework Component (CVE-2026-0047): A serious Elevation of Privilege (EoP) vulnerability exists that does not need user interaction to be exploited. The 2026-03-05 patch level fixes 66 vulnerabilities mainly found in hardware drivers and the Linux kernel.
This update includes important patches for the Protected Kernel-Based Virtual Machine (pKVM) and Hypervisor, like CVE-2026-0038 and CVE-2026-0027, essential for keeping your apps and data separate.
Summary of Major Components Impacted
| Component |
Key Vulnerabilities |
Top Severity |
| Framework |
32 total |
Critical |
| System |
19 total |
Critical |
| Kernel |
15 total |
Critical |
| Qualcomm |
Includes exploited CVE-2026-21385 |
High |
Android users are urged to check their Settings > System > System update immediately to ensure they are running the latest security version.