Skip to main content
Showing 30 of 30 advisoryies

Google Cloud Security Bulletins

Apr 7, 2026
GCP-2026-018

2026-04-15 Update: Added patch versions for Ubuntu nodes with GKE.

GCP-2026-018CVE-2026-23111High
Apr 2, 2026
GCP-2026-017

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23273 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-017CVE-2026-23273High
Mar 27, 2026
GCP-2026-016

2026-03-31 Update: Added patch versions for Ubuntu nodes with GKE.

GCP-2026-016CVE-2025-38616High
Mar 27, 2026
GCP-2026-015

The following vulnerability was discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23268.

GCP-2026-015CVE-2026-23268High
Mar 14, 2026
GCP-2026-014

2026-03-25 Update: Added patch versions for Ubuntu nodes with GKE.

GCP-2026-014CVE-2025-38678High
Mar 11, 2026
GCP-2026-013

The following vulnerabilities were discovered in Envoy Proxy: CVE-2026-26311 CVE-2026-26309 CVE-2026-26310 CVE-2026-26308 CVE-2026-26330 The following vulnerabilities were discovered in Istio: CVE-2026-31837 CVE-2026-31838 For instructions and more details, see the Cloud Service Mesh security bulletin.

GCP-2026-013CVE-2026-26311CVE-2026-26309CVE-2026-26310CVE-2026-26308CVE-2026-26330CVE-2026-31837CVE-2026-31838
Feb 20, 2026
GCP-2026-012

In Google Cloud Vertex AI, a vulnerability involving predictable bucket naming was identified in Vertex AI Experiments from version 1.

GCP-2026-012CVE-2026-2473High
Feb 20, 2026
GCP-2026-011

A stored Cross-site Scripting (XSS) vulnerability in _genai/_evals_visualization was identified in Google google-cloud-aiplatform (Vertex AI Python SDK Visualization) on Exclusively-Hosted-Service.

GCP-2026-011CVE-2026-2472High
Feb 13, 2026
GCP-2026-010

A vulnerability was identified in the Apigee platform that could have allowed a malicious actor with administrative or developer-level permissions in their own Apigee environment to elevate privileges and access cross-tenant data.

GCP-2026-010CVE-2025-13292High
Feb 13, 2026
GCP-2026-009

Observability Analytics user interface versions prior to January 2026 can be configured to automatically execute SQL queries.

GCP-2026-009High
Feb 10, 2026
GCP-2026-008

A set of security vulnerabilities affect Intel® TDX firmware.

GCP-2026-008CVE-2025-30513CVE-2025-31944CVE-2025-32007CVE-2025-27940CVE-2025-32467CVE-2025-27572High
Feb 9, 2026
GCP-2026-007

2026-03-25 Update: Added patch versions for Ubuntu nodes with GKE.

GCP-2026-007CVE-2025-40297High
Jan 29, 2026
GCP-2026-006

2026-02-20 Update: Added patch versions for GKE.

GCP-2026-006CVE-2025-15467High
Jan 28, 2026
GCP-2026-005

This vulnerability affects Log Analytics interface and Cloud Monitoring dashboarding interface versions prior to January 2026.

GCP-2026-005High
Apr 16, 2026
GCP-2026-022

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23209 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-022CVE-2026-23209High
Apr 14, 2026
GCP-2026-021

AMD reported a vulnerability in its firmware that could have allowed a malicious hypervisor to direct the IOMMU to write into the guest memory of AMD SEV-SNP enabled instances, compromising guest data integrity.

GCP-2026-021CVE-2023-20585Medium
Apr 14, 2026
GCP-2026-020

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23231 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-020CVE-2026-23231High
Apr 14, 2026
GCP-2026-019

Researchers discovered a vulnerability in AMD firmware that could allow a malicious hypervisor to alter BIOS settings and Memory Mapped I/O (MMIO) routing configurations, compromising the confidentiality and integrity of Confidential VMs with AMD SEV-SNP guests.

GCP-2026-019CVE-2025-54510Medium
Apr 28, 2026
GCP-2026-023

2026-05-07 Update: Added patch versions for Ubuntu node pools on GKE The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23074 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-023CVE-2026-23074High
Apr 28, 2026
GCP-2026-024

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes: CVE-2025-38248 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-024CVE-2025-38248High
Apr 30, 2026
GCP-2026-026

2026-05-04 Update: Added patch versions for GKE.

GCP-2026-026CVE-2026-31431High
Apr 30, 2026
GCP-2026-025

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23274 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-025CVE-2026-23274High
May 1, 2026
GCP-2026-027

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23351 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin

GCP-2026-027CVE-2026-23351High
May 7, 2026
GCP-2026-029

Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software.

GCP-2026-029
May 5, 2026
GCP-2026-028

CVE-2026-31431, also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access.

GCP-2026-028CVE-2026-31431High
May 11, 2026
GCP-2026-030

2026-05-20 Update: Added CVE-2026-43500 and added CVE IDs to exploit paths.

GCP-2026-030CVE-2026-43500CVE-2026-43284High
May 12, 2026
GCP-2026-032

AMD has identified a hardware-level vulnerability in Zen 2 microarchitecture processors (including EPYC and Ryzen series) involving potential corruption within the micro-operation (OP) cache.

GCP-2026-032CVE-2025-54518High
May 12, 2026
GCP-2026-031

Researchers discovered a vulnerability in AMD firmware that, due to missing protection, could allow a malicious hypervisor to execute arbitrary code on the AMD Secure Processor (ASP).

GCP-2026-031CVE-2025-61971CVE-2025-61972CVE-2024-36315Medium
May 14, 2026
GCP-2026-033

A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia.

GCP-2026-033CVE-2026-46300Medium
May 20, 2026
GCP-2026-034

A vulnerability was found in Apigee where the IntegrationRegion parameter in the SetIntegrationRequest policy lacks validation, allowing for Server-Side Request Forgery (SSRF) and service account token exfiltration.

GCP-2026-034CVE-2026-2264High