Track Google with a free Huntertech account. Get outage alerts, watchlists, and cross-vendor monitoring in one place.

Try for free
31 advisories in the last 7 days/33 total historical

Google advisories

Security and product notices from the vendor feed - scan the last seven days or browse the full set. Refine by cloud, timeframe, and search.

Updated about 1 hour ago
No cloud names detected.

Advisories

Advisories

Showing 25 of 33 advisories
Apr 16, 2026
GCP-2026-022HighCVE-2026-23209
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23209 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin
Apr 28, 2026
GCP-2026-023HighCVE-2026-23074
Added patch versions for Ubuntu node pools on GKE The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23074 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin
Apr 28, 2026
GCP-2026-024HighCVE-2025-38248
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes: CVE-2025-38248 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin
Apr 30, 2026
GCP-2026-026HighCVE-2026-31431
Added patch versions for GKE.
Apr 30, 2026
GCP-2026-025HighCVE-2026-23274
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23274 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin
May 1, 2026
GCP-2026-027HighCVE-2026-23351
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: CVE-2026-23351 For instructions and more details, see the following bulletins: GKE security bulletin GDC software for VMware security bulletin GKE on AWS security bulletin GKE on Azure security bulletin GDC software for bare metal security bulletin
May 7, 2026
GCP-2026-029
Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software.
May 5, 2026
GCP-2026-028HighCVE-2026-31431
CVE-2026-31431 , also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access.
May 11, 2026
GCP-2026-030HighCVE-2026-43500CVE-2026-43284
Added patch versions for GKE.
May 12, 2026
GCP-2026-032HighCVE-2025-54518
AMD has identified a hardware-level vulnerability in Zen 2 microarchitecture processors (including EPYC and Ryzen series) involving potential corruption within the micro-operation (OP) cache.
May 12, 2026
GCP-2026-031MediumCVE-2025-61971CVE-2025-61972CVE-2024-36315
Researchers discovered a vulnerability in AMD firmware that, due to missing protection, could allow a malicious hypervisor to execute arbitrary code on the AMD Secure Processor (ASP).
May 14, 2026
GCP-2026-033MediumCVE-2026-46300
The following versions of GKE are updated with code to fix this vulnerability on Ubuntu.
May 20, 2026
GCP-2026-034HighCVE-2026-2264
A vulnerability was found in Apigee where the IntegrationRegion parameter in the SetIntegrationRequest policy lacks validation, allowing for Server-Side Request Forgery (SSRF) and service account token exfiltration.
Jun 8, 2026
GCP-2026-035HighCVE-2026-47774
A vulnerability was found in Envoy where HTTP/2 downstream request processing allow an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM termination of the Envoy process and denial of service.
Jun 9, 2026
GCP-2026-036HighCVE-2025-10263
ARM has announced CVE-2025-10263, an architectural issue affecting some Arm cores which lets an attacker bypass translation stages or GPT protections under certain conditions.
Jun 18, 2026
GCP-2026-037CriticalCVE-2026-50195CVE-2026-53488CVE-2026-53492CVE-2026-53489CVE-2026-47262
Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions 1.
Jun 22, 2026
GCP-2026-039Medium
A vulnerability in Cloud Logging could have allowed attackers to hijack log sink destinations by recreating the target Cloud Storage bucket in a project controlled by the attacker.
Jun 22, 2026
GCP-2026-038HighCVE-2026-8934
A vulnerability was found in App Engine where the GetDashboardAppStats GraphQL private API operation in the Google Cloud console leaked cross-tenant request logs.
Jun 23, 2026
GCP-2026-040CVE-2026-47692CVE-2026-47207CVE-2026-47205CVE-2026-47220CVE-2026-47221CVE-2026-48044CVE-2026-48090CVE-2026-47778CVE-2026-47204CVE-2026-48497CVE-2026-48706CVE-2026-48743CVE-2026-47775CVE-2026-48042
A series of vulnerabilities were discovered in Envoy Proxy.
Jun 24, 2026
GCP-2026-043HighCVE-2026-12715
A vulnerability was found in Firebase Studio where the GetSignedGcsUrl RPC allowed authenticated users to list buckets and download deployment source code of other tenants.
Jun 24, 2026
GCP-2026-042Low
A privilege escalation vulnerability was addressed in Cloud Build.
Jun 24, 2026
GCP-2026-041HighCVE-2026-34480CVE-2026-34477
A recent security investigation was conducted regarding log4j vulnerabilities (CVE-2026-34480 and CVE-2026-34477) reported in Apigee Edge for Private Cloud.
Jun 25, 2026
GCP-2026-044HighCVE-2025-0982
A vulnerability was detected in Application Integration's JavaScript task, which was using the Rhino JavaScript engine.
Jul 6, 2026
GCP-2026-046CVE-2026-53359
A virtualization vulnerability has been identified in the KVM x86 shadow paging and nested virtualization configurations.
Jun 29, 2026
GCP-2026-045High
A vulnerability was detected in Envoy Proxy where blocked QPACK decoding can cause a Denial-of-Service Attack against the HTTP/3 stack.

Data access

Unlock more advisories for Google

You're seeing 33 advisories from the last 7 days without signing in.

Public session

Public

Next step: Free - 7 days history and full feed tools. No card required to start.

What you can unlock

Higher tiers unlock more history and more rows.

  • Recommended next step

    Free

    Same 7 days window ยท adds plan perks

    • Incidents, maintenance, updates, and advisories
    • Unlimited vendor monitoring
    • Analytics and trends
    Alerts

    Plan perks

  • Standard

    30 days history

    • Everything in Free
    • Analytics
    • Compliance snapshots
    Alerts

    Wider window

  • Pro

    90 days history

    • Everything in Standard
    • Analytics
    • REST API

    Wider window