CERT-In Flags Critical Vulnerabilities This Week
India's Computer Emergency Response Team (CERT-In), the government's nodal agency for cybersecurity incidents, has issued a cluster of high-severity security advisories in the week of September 15–20, 2026, affecting hundreds of millions of Indian users across Apple iOS, macOS, Android, Google Chrome, and Microsoft products.
These are not theoretical threats. Advisories at the "high" and "critical" severity level from CERT-In indicate vulnerabilities that are either already being actively exploited by attackers or carry realistic potential for exploitation in the near term. For Indian users — particularly given the scale of UPI, digital banking, and government e-services on mobile devices — staying current on security patches is not optional.
Image: Unsplash / Cybersecurity
Apple: iOS, iPadOS, macOS, Safari — Multiple Flaws
CERT-In's advisory for Apple products covers vulnerabilities across iOS 26, iPadOS 26, macOS Tahoe 26, Safari, and watchOS. The most serious issues include:
- Memory corruption vulnerabilities in WebKit (the browser engine used by Safari and all third-party browsers on iOS) that could allow an attacker to execute arbitrary code by getting a user to visit a maliciously crafted webpage.
- Authentication bypass flaws that could allow an attacker to bypass security restrictions in certain conditions.
- Information disclosure vulnerabilities that could expose sensitive user data to a remote attacker.
What to do: Update to the latest iOS and macOS versions immediately via Settings → General → Software Update on iPhone/iPad, and System Settings → General → Software Update on Mac.
Android: September 2026 Security Patch Is Critical
Google's September 2026 Android Security Bulletin — released in line with its regular monthly cadence — addresses over 35 vulnerabilities, including several rated Critical. The most dangerous include flaws in the Android kernel and system components that could allow privilege escalation or remote code execution without requiring any user interaction.
CERT-In has specifically flagged that Indian users on older Android versions (Android 12 and below) running devices that no longer receive security updates are at elevated risk. With a significant portion of India's smartphone base running older Android versions on budget devices, this is a population-scale concern.
What to do: Check for the September 2026 security patch in Settings → About Phone → Android Security Patch Level. If your device manufacturer has released the patch, install it immediately.
Google Chrome: High-Severity Flaws Fixed
Google released Chrome 128 with patches for multiple high-severity vulnerabilities in the same week, including use-after-free bugs and type confusion errors in the V8 JavaScript engine — classes of vulnerability that are frequently exploited in browser-based attacks. Chrome auto-updates for most users, but verifying your version is best practice.
What to do: Open Chrome → three-dot menu → Help → About Google Chrome. If an update is available, it will install automatically and prompt you to relaunch the browser.
Microsoft: Windows and Office Patches
September 2026's Microsoft Patch Tuesday (the second Tuesday of each month) addressed over 60 vulnerabilities across Windows 11, Windows 10, Microsoft Office 365, Azure, and Exchange Server. Several are rated Critical, including a zero-click remote code execution flaw in Microsoft Outlook that requires no user action beyond receiving a malicious email.
What to do: Windows Update (Settings → Windows Update → Check for Updates). For enterprise users, coordinate with your IT team to deploy patches through WSUS or Microsoft Intune.
The Bigger Picture: AI-Powered Cyberattacks Rising
CERT-In's September 2026 advisories come amid a broader trend that security analysts have been tracking throughout 2026: the use of AI tools — including large language models and automated vulnerability scanning — by both state-sponsored hackers and criminal groups to accelerate attack preparation. India's growing digital economy, including the UPI payments network that now processes billions of transactions monthly, makes it an increasingly attractive target.
India's National Cyber Security Policy update (under discussion through 2026) is expected to mandate shorter patch-deployment windows for critical infrastructure operators and financial institutions — a response to the speed at which AI-assisted attacks can weaponize known vulnerabilities.
Key Takeaways
- CERT-In has issued high-severity advisories affecting Apple, Android, Chrome, and Microsoft products in September 2026.
- Update iOS/macOS, install Android's September 2026 security patch, and verify Chrome is updated to version 128+.
- A zero-click Microsoft Outlook vulnerability is among the most dangerous — enterprise users should prioritise patching.
- AI-assisted cyberattacks are increasing in frequency and sophistication in 2026.
Frequently Asked Questions
How do I check if my phone has the September 2026 Android patch?
Go to Settings → About Phone → Android Security Patch Level. It should show "September 2026" or the date of the most recent patch.
What is CERT-In?
CERT-In (Indian Computer Emergency Response Team) is India's national cybersecurity agency under the Ministry of Electronics and Information Technology (MeitY). It monitors threats and issues advisories to help Indian users and organisations stay protected.
Is UPI safe from these vulnerabilities?
NPCI and banks implement server-side security independently of device OS vulnerabilities. However, device-level vulnerabilities can expose your UPI PIN or banking app data to attackers — keeping your phone updated is the primary protection.
Conclusion
Cybersecurity updates are the digital equivalent of locking your front door. CERT-In's September 2026 advisories cover vulnerabilities that are serious, real, and in some cases already being exploited. For the overwhelming majority of Indian users, the action is simple: go to your phone's settings right now and check for an update. It takes five minutes. Not doing it could cost considerably more.