Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Google Cloud — Vulnerabilities & Security Advisories 56

Browse all 56 CVE security advisories affecting Google Cloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Google Cloud operates as a comprehensive suite of cloud computing services, providing infrastructure, platform, and software solutions for enterprise data storage, analytics, and application development. With thirty-one recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex integration points or third-party dependencies. Security assessments indicate that while the underlying infrastructure maintains robust isolation mechanisms, application-layer vulnerabilities frequently arise from misconfigurations or unpatched components within managed services. Notable incidents have primarily involved data exposure risks due to incorrect access controls rather than systemic infrastructure breaches. The platform continues to implement rigorous patch management and automated security scanning to mitigate these risks, emphasizing the importance of proper configuration by end-users to maintain the integrity of deployed workloads within the broader Google ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-81375 Confused Deputy in Application Integration allows Internal File Read — Application Integration CWE-610 8.3 High 2026-09-28
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution — Application Integration CWE-502 9.4 Critical 2026-09-28
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution — Application Integration CWE-863 9.4 Critical 2026-09-28
CVE-2026-19407 GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK — Gemini Enterprise Agent Platform SDK for Python CWE-330 7.7 High 2026-09-15
CVE-2026-19486 SSRF in Gemini Enterprise Agent Platform App Builder — Gemini Enterprise Agent Platform App Builder CWE-918 8.7 High 2026-09-11
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOME — Gemini CLI CWE-829 7.7 High 2026-09-10
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist — Agent Development Kit (ADK) for Python CWE-184 10.0 Critical 2026-09-09
CVE-2026-4644 Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover — Integration Connectors CWE-863 8.5 High 2026-09-04
CVE-2026-79707 Arbitrary File Read in Google Agent Development Kit (ADK) — Agent Development Kit (ADK) CWE-22 8.7 High 2026-09-04
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression — Google Cloud Build CWE-367 9.4 Critical 2026-08-31
CVE-2026-19485 Bucket Squatting in Vertex AI Search for Commerce — Vertex AI Search for Commerce CWE-330 9.3 Critical 2026-08-26
CVE-2026-12717 Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection — BigQuery Data Transfer Service CWE-74 9.4 Critical 2026-08-26
CVE-2026-12710 Missing Authorization in Application Integration QueryEngineTask — Application Integration CWE-862 9.3 Critical 2026-08-22
CVE-2026-15623 Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service — Google SecOps (Chronicle SOAR) CWE-89 9.4 Critical 2026-08-17
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header — Google SecOps (Chronicle SOAR) CWE-346 9.4 Critical 2026-08-05
CVE-2026-15810 Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover — Looker CWE-79 8.7 High 2026-07-24
CVE-2026-12715 Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft — Firebase Studio CWE-862 - - 2026-07-17
CVE-2026-14934 Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise — BigQuery CWE-862 - - 2026-07-13
CVE-2026-12879 Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy — Apigee CWE-610 - - 2026-07-09
CVE-2026-12537 Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows — Gemini CLI CWE-20 - - 2026-06-24
CVE-2026-8934 Cross-Project Information Leakage in Google App Engine UI — Cloud Console UIs CWE-862 - - 2026-06-22
CVE-2026-4764 Privilege Escalation in Dialogflow CX via Playbook Import — Dialogflow CX CWE-862 - - 2026-06-11
CVE-2026-2264 Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy. — Apigee-X CWE-918 - - 2026-05-26
CVE-2026-2031 Google Cloud Application Integration: Exposed internal APIs allow Information Disclosure and Remote Code Execution. — Internal Integration Platform APIs CWE-862 - - 2026-05-15
CVE-2026-7428 Insecure default administrative credentials in AlloyDB for PostgreSQL — AlloyDB for PostgreSQL CWE-1392 - - 2026-05-12
CVE-2026-3259 Sensitive Data Disclosure in BigQuery via Materialized View Error Messages — BigQuery CWE-209 4.3AI Medium AI 2026-04-23
CVE-2026-4810 Remote Code Execution in Google Agent Development Kit (ADK) — Agent Development Kit (ADK) CWE-306 9.8 - 2026-04-13
CVE-2026-3136 Google Cloud Build Comment Control Bypass — Cloud Build CWE-863 9.8AI Critical AI 2026-03-03
CVE-2026-2244 Sensitive Data Exposure in Google Cloud Vertex AI Workbench — Vertex AI Workbench CWE-200 7.5AI High AI 2026-02-26
CVE-2026-2473 Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft. — Vertex AI Experiments CWE-340 9.8AI Critical AI 2026-02-20

This page lists every published CVE security advisory associated with Google Cloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.