Junglewise Threat Intelligence

CVE-2026-20901: Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an

CVE-2026-20901 · Severity: high · Published 2026-08-11

Technologies: Google Cloud Platform. Vendors: Google, Intel.

Executive brief

Intel Trust Domain Extensions (TDX) firmware used in Google Cloud Confidential VMs contains multiple security vulnerabilities that could allow a privileged host administrator to bypass security checks, access restricted memory areas, or decrypt guest data. This undermines the foundational security guarantee of Confidential VMs—that cloud provider administrators cannot access customer workload data. Google has already patched all affected servers and no customer action is required.

Technical details

These vulnerabilities affect Intel TDX firmware used to isolate and protect guest virtual machines from host-level access. The flaws allow a privileged host adversary to bypass attestation verification mechanisms, access restricted TDX module registers, or decrypt guest memory that should remain confidential. The attack requires high-level host privileges (kernel-level or hypervisor access) but no guest-side interaction or network access. Google has proactively deployed firmware patches across the entire server fleet; customers who did not receive direct upgrade notification are already protected.

Affected products

  • Intel Trust Domain Extensions (TDX) firmware
  • Google Compute Engine Confidential VMs

CVE identifiers

  • CVE-2026-20901
  • CVE-2025-31938
  • CVE-2026-20705
  • CVE-2026-20898
  • CVE-2025-35973
  • CVE-2026-20713
  • CVE-2026-20775
  • CVE-2026-20885
  • CVE-2025-31356

Timeline

  • 2026-08-11: disclosed: GCP-2026-053 published
  • 2026-08-11: patched: Google proactively applied firmware upgrades to server fleet

References

Related threats