Picture the drawer in your nonprofit’s office where the spare phones live. The two-year-old Androids that get handed to a new hire on day one, or grabbed for a field event, or used to run the donation kiosk at the gala. Nobody owns those phones, exactly. And nobody updates them.
That drawer is the reason this week’s Android news matters to you.
On Tuesday, Google released patches for 180 vulnerabilities as part of the September 2026 Android security updates. According to SecurityWeek, this came after two straight bulletins in July and August that reported no security vulnerabilities at all. So the volume jumped from nothing to 180 in a single month.
What Google actually patched
The update arrives in two parts, split the way Android updates usually are.
The first part, the 2026-09-01 patch level, resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and several Project Mainline components. According to SecurityWeek’s reporting, Google’s advisory describes the most severe issue as a critical vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed, and no user interaction required to exploit it.
That System component matters more than the name suggests. As Jamf’s Adam Boynton told SecurityWeek, the System is responsible for most of a phone’s core functionality, like app operation, and many of the critical updates this month land there. The refresh addresses 56 security defects in the System component alone, including 23 critical flaws.
Boynton flagged one specifically. According to SecurityWeek, he pointed to CVE-2026-28662, a Wi-Fi-related memory corruption flaw, as most concerning on the list. If left unpatched, he said, it could enable attackers to execute code remotely without any additional privileges or user interaction, potentially allowing privilege escalation. His recommendation was direct: organizations should issue the updates across their device fleet as soon as possible.
The second part, the 2026-09-05 patch level, contains fixes for 85 defects across Android’s kernel and its components, as well as TV, Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc, and Qualcomm components. Devices updated to that patch level or newer carry fixes for everything in this bulletin plus the earlier ones.
Why this lands harder on a nonprofit
Here is the part that connects the drawer to the news.
A Wi-Fi flaw that needs no user interaction means nobody on your team has to click anything, download anything, or make a mistake. The exposure sits in the device itself until it gets patched. That changes who is at risk. It is not just the people who fall for phishing. It is everyone carrying an unpatched phone within range of a network an attacker controls.
Nonprofits carry a specific kind of exposure here. Your phones hold donor contact lists, gift histories, board member communications, and sometimes access to the CRM or the payment platform you use at events. That data is the trust your donors placed in you. And unlike a corporation with a locked-down device management system, a lot of nonprofits run on a mix of personal phones, hand-me-down phones, and that unowned drawer.
The budget reality makes it worse. Older Android devices stop receiving security updates entirely at a certain age. A phone that cannot install the September patch is not behind by one month. It is permanently exposed to this flaw and every future one. For a nonprofit stretching hardware to save money, that tradeoff is invisible until it is not.
What to do this week
You do not need a big IT budget to close most of this gap. You need a short, boring checklist and someone to run it.
-
Update every Android phone your organization touches. Settings, System, System update, check now. Do it on your own phone first, then walk the office.
-
Confirm the patch level, not just the Android version. On each device, look under Settings for the Android security update date. You want 2026-09-05 or newer. The version number alone does not tell you whether this month’s fixes landed.
-
Open the drawer. Find every spare, shared, and forgotten device. Update it or retire it. A phone nobody owns is a phone nobody patches.
-
Check the phones that touch donor data or payments first. Event kiosks, the phone linked to your giving platform, the board chair’s device. Prioritize by what the phone can reach.
-
Retire what cannot be patched. If a device no longer receives Android security updates, it should no longer hold donor data or connect to your systems. Write down which phones those are and set a replacement date.
None of this requires a consultant. It requires an hour and a list. The phones that hurt you are the ones nobody remembered to check.
That drawer full of spare Androids is not a convenience. Until every phone in it is updated or gone, it is the door you left unlocked.
Common Questions
How do I check which Android security patch level my phone has? Open Settings, then look under About phone or System for the Android security update date. This month you want to see 2026-09-05 or newer. That date, not the Android version number, tells you whether September’s fixes are installed.
Do our phones need an update if nobody clicks on anything suspicious? Yes. According to SecurityWeek’s reporting on this bulletin, several of the critical flaws, including a Wi-Fi memory corruption bug, require no user interaction to exploit. The risk exists on the device regardless of how careful your team is, until the patch is applied.
What should we do with old phones that no longer get updates? Retire them from any role that touches donor data, payments, or your organization’s systems. A device that can no longer install security patches stays exposed to this flaw and future ones. Set a replacement plan for anything that has aged out of support.
Does this affect tablets and other Android devices too? The September bulletin covers Android broadly. If a device runs Android and can receive the update, it should be brought to the 2026-09-05 patch level or newer. Devices that cannot reach that level should be evaluated for retirement.
Sources
- Google released patches for 180 Android vulnerabilities in September 2026 after two bulletins with none: SecurityWeek, “Android’s September 2026 Updates Patch 180 Vulnerabilities” (2026), https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
- The most severe flaw is a critical System component bug allowing remote code execution with no user interaction: SecurityWeek, “Android’s September 2026 Updates Patch 180 Vulnerabilities” (2026), https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
- Jamf’s Adam Boynton identified CVE-2026-28662, a Wi-Fi memory corruption flaw, as most concerning: SecurityWeek, “Android’s September 2026 Updates Patch 180 Vulnerabilities” (2026), https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
centrexIT has been the IT team Nonprofit organizations across the West have trusted since 2002. Your mission runs on the trust donors place in you, and that trust lives on the devices your team carries. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team