Browse all 56 CVE security advisories affecting Google Cloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Google Cloud operates as a comprehensive suite of cloud computing services, providing infrastructure, platform, and software solutions for enterprise data storage, analytics, and application development. With thirty-one recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex integration points or third-party dependencies. Security assessments indicate that while the underlying infrastructure maintains robust isolation mechanisms, application-layer vulnerabilities frequently arise from misconfigurations or unpatched components within managed services. Notable incidents have primarily involved data exposure risks due to incorrect access controls rather than systemic infrastructure breaches. The platform continues to implement rigorous patch management and automated security scanning to mitigate these risks, emphasizing the importance of proper configuration by end-users to maintain the integrity of deployed workloads within the broader Google ecosystem.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-81375 | Confused Deputy in Application Integration allows Internal File Read — Application Integration CWE-610 | 8.3 | High | 2026-09-28 |
| CVE-2026-81867 | Deserialization of Untrusted Data in Application Integration allows Remote Code Execution — Application Integration CWE-502 | 9.4 | Critical | 2026-09-28 |
| CVE-2026-19759 | Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution — Application Integration CWE-863 | 9.4 | Critical | 2026-09-28 |
| CVE-2026-12710 | Missing Authorization in Application Integration QueryEngineTask — Application Integration CWE-862 | 9.3 | Critical | 2026-08-22 |
| CVE-2025-0982 | Sandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine) — Application Integration CWE-829 | 10.0 | - | 2025-02-06 |
This page lists every published CVE security advisory associated with Google Cloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.