Xiaomi September 2026 Update: 180 Critical Fixes Explained

Xiaomi has begun distributing its September 2026 security update across its device portfolio, with the first wave currently tied closely to the company’s HyperOS 4 rollout. The update is primarily appearing on devices receiving HyperOS 4 in China, although some global models have also started seeing HyperOS 4 through open-beta channels. Xiaomi is expected to expand the September security patch to additional devices, including models that remain on earlier HyperOS software versions.

That distinction is important. The September security patch is not the same thing as HyperOS 4. Some devices are receiving both together because their latest software build is HyperOS 4, while other Xiaomi, Redmi, and POCO devices can receive the same month’s security fixes through a different HyperOS build. As of September 23, the currently reported rollout includes the following devices and builds.

Xiaomi Devices Receiving the September 2026 Patch

Region Build
Xiaomi 15 Global OS4.0.0.7.XOCMIXM
Xiaomi 15 EEA OS4.0.0.9.XOCEUXM
Xiaomi 15 Ultra Global OS4.0.0.6.XOAMIXM
Xiaomi 15 Ultra EEA OS4.0.0.6.XOAEUXM
Xiaomi 17T EEA OS4.0.0.7.XPTEUXM
Xiaomi 17T Pro EEA OS4.0.0.6.XPSEUXM
Xiaomi MIX Flip 2 China OS4.0.0.10.XOHCNXM
Xiaomi Pad 7S Pro 12.5 China OS4.0.0.11.XOTCNXM

The list shows that the rollout is not confined entirely to China. The Xiaomi 15 and Xiaomi 15 Ultra are already represented in both Global and EEA builds, while the Xiaomi 17T and 17T Pro are currently listed for the EEA region.

The MIX Flip 2 and Pad 7S Pro 12.5, meanwhile, are appearing with Chinese HyperOS 4 builds.

Redmi Devices Getting the September Security Update

The Redmi portion of the current rollout is concentrated on several high-end models:

Region Build
Redmi K80 China OS4.0.0.8.XOKCNXM
Redmi K80 Pro China OS4.0.0.8.XOMCNXM
Redmi K100 Pro Max China OS4.0.0.8.XGNCNXM

These builds are also relevant to the corresponding POCO models listed below, reflecting the relationship between Xiaomi’s regional device lineups and their software releases.

Xiaomi September 2026 Update: 180 Critical Fixes Explained 1

The current Redmi list should not be treated as the final compatibility list. Xiaomi is still expanding the September patch rollout, and additional Redmi models are expected to appear as their respective builds become available.

POCO Devices Receiving the Update

The current POCO rollout includes three models:

Region Build
POCO F7 Pro China OS4.0.0.8.XOKCNXM
POCO F7 Ultra China OS4.0.0.8.XOMCNXM
POCO F9 Ultra China OS4.0.0.8.XGNCNXM

Interestingly, the builds correspond directly with the Redmi devices listed above. The POCO F7 Pro shares its listed build with the Redmi K80, while the F7 Ultra and F9 Ultra correspond with the K80 Pro and K100 Pro Max builds, respectively.

For POCO owners, however, the appearance of a model on this list does not necessarily mean the update will immediately appear in every market. Region-specific software branches can have different rollout schedules.

What Does the September 2026 Android Security Patch Fix?

The security component of this release is considerably larger than a routine software update might suggest.

Google’s September 2026 Android Security Bulletin addresses 180 vulnerabilities across Android. The fixes are divided between the September 1 and September 5 security patch levels, with the later level incorporating the applicable fixes from the earlier level as well as additional issues. Of the 180 fixes referenced in the Xiaomi rollout, 95 address vulnerabilities in Android’s core system and framework, while another 85 target hardware-specific components.

The hardware-related fixes cover components and drivers associated with vendors including Qualcomm, Arm, MediaTek, Imagination Technologies and Unisoc. Not every vulnerability listed in Google’s Android bulletin will necessarily affect every Xiaomi, Redmi or POCO device. Hardware configurations, Android versions, chipsets and software builds differ between models, so the applicable fixes depend on the particular device.

A Critical RCE Vulnerability Is Also Included

One of the most important reasons to install the September patch when it reaches a supported device is the presence of a critical remote code execution vulnerability.

Google describes the most severe issue in its September bulletin as a vulnerability in the Android System component that could allow remote code execution without additional execution privileges and without requiring user interaction. Google’s bulletin also lists multiple critical RCE vulnerabilities affecting the System component, alongside other critical elevation-of-privilege and denial-of-service issues.

HyperOS 4, july 2026 security update
Representational image: News

The existence of these vulnerabilities does not mean that every Xiaomi phone is exposed to every issue in the bulletin. The actual protection delivered by a Xiaomi update depends on which patches are applicable to that model and software branch.

HyperOS 4 and the Security Patch Are Not the Same Update

The connection between this security rollout and HyperOS 4 can make Xiaomi’s update situation confusing.

The first group of devices reported with the September security patch is receiving it as part of HyperOS 4 builds. Xiaomi’s current HyperOS 4 rollout is concentrated primarily in China, while some global and EEA devices are seeing beta or region-specific releases. That does not mean every Xiaomi phone that receives the September 2026 security patch must also jump to HyperOS 4.

Xiaomi can distribute the September security fixes through a different HyperOS software build for devices that have not yet moved to HyperOS 4. In fact, reports already show September security patches appearing on some HyperOS 3.1 builds, demonstrating that the security patch level and major operating-system skin version are separate concepts. For users, the practical takeaway is simple: check the security patch date and build offered to your specific device.

How to Check for the September 2026 Update

If your Xiaomi, Redmi, or POCO device has not shown an update notification, you can check manually.

Settings → About phone → HyperOS → Check for updates

Depending on the device and software version, the exact wording may vary slightly. If no update appears, that does not necessarily mean your phone has been excluded. Xiaomi uses staged rollouts, so an update can reach some users before others, even when they own the same model. Regional software branches can also affect availability. A build released for China, Global or EEA markets will not necessarily become available simultaneously across all regions.

Xiaomi SkyNomad Xiaomi Swiss Knife New Xiaomi 18 Leak
Representational Image: News

More Xiaomi, Redmi and POCO Devices Should Follow

The September 2026 security update rollout is still in its early stages. The current list represents the devices reported to be receiving the update at this point. More models should be added as Xiaomi prepares and distributes additional software builds. Some devices will receive the security fixes through HyperOS 4, while others can get them through existing HyperOS branches.

For now, Xiaomi users can check their device manually and look specifically at the security patch level and software build being offered. The September release is particularly notable because Google’s bulletin covers 180 vulnerabilities, including critical issues involving remote code execution. The rollout will continue to expand across Xiaomi, Redmi, and POCO devices as additional regional builds become available.

(Source)

Leave a Comment