{"schema_version":1,"title":"Google Cloud Platform vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 29 vulnerabilities in Google Cloud Platform: 1 in the last 7 days and 18 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73513, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/google-cloud-platform","json_url":"https://junglewise.ai/threats/technologies/google-cloud-platform.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/google-cloud-platform","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":21,"all_time":29,"critical":1,"exploited":0,"last_7_days":1,"last_30_days":6,"last_90_days":18,"last_365_days":29},"latest":[{"cve":"CVE-2026-73513","cvss":7.5,"epss":0.0072,"slug":"cve-2026-73513-envoy-proxy-multiple-vulnerabilities","title":"Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:27.82+00:00","url":"https://junglewise.ai/threats/cve-2026-73513-envoy-proxy-multiple-vulnerabilities"},{"cve":"CVE-2026-15587","slug":"cve-2026-15587-google-security-operations-soar-privilege-escalation-via","title":"Google Security Operations SOAR privilege escalation via authentication header","severity":"high","exploited":false,"published_at":"2026-09-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-15587-google-security-operations-soar-privilege-escalation-via"},{"cve":"CVE-2026-65107","slug":"cve-2026-65107-slurm-sbcast-shared-library-validation-bypass","title":"Slurm multiple vulnerabilities in Cluster Toolkit","severity":"high","exploited":false,"published_at":"2026-09-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-65107-slurm-sbcast-shared-library-validation-bypass"},{"slug":"containerd-cri-security-context-bypass-in-checkpoint-restore-d7cf36e0","title":"containerd CRI security context bypass in checkpoint restore","severity":"info","exploited":false,"published_at":"2026-09-09T00:00:00+00:00","url":"https://junglewise.ai/threats/containerd-cri-security-context-bypass-in-checkpoint-restore-d7cf36e0"},{"cve":"CVE-2026-4644","epss":0.0035,"slug":"cve-2026-4644-google-cloud-integration-connectors-http-missing-authorization","title":"A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud","severity":"high","exploited":false,"published_at":"2026-09-04T11:17:18.83+00:00","url":"https://junglewise.ai/threats/cve-2026-4644-google-cloud-integration-connectors-http-missing-authorization"},{"slug":"google-gke-multi-cloud-authorization-bypass-in-cluster-registration-af138b69","title":"Google GKE Multi-Cloud authorization bypass in cluster registration APIs","severity":"info","exploited":false,"published_at":"2026-09-02T00:00:00+00:00","url":"https://junglewise.ai/threats/google-gke-multi-cloud-authorization-bypass-in-cluster-registration-af138b69"},{"cve":"CVE-2026-12717","epss":0.0045,"slug":"cve-2026-12717-google-bigquery-data-transfer-service-jdbc-driver-input","title":"An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to","severity":"high","exploited":false,"published_at":"2026-08-26T14:17:07.25+00:00","url":"https://junglewise.ai/threats/cve-2026-12717-google-bigquery-data-transfer-service-jdbc-driver-input"},{"cvss":9.8,"slug":"next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345","title":"Next.js and libheif RCE in HEIF/AVIF image processing","severity":"info","exploited":false,"published_at":"2026-08-25T00:00:00+00:00","url":"https://junglewise.ai/threats/next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345"},{"cve":"CVE-2025-31938","epss":0.0009,"slug":"cve-2025-31938-intel-tdx-firmware-confidential-vm-escape","title":"Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an","severity":"high","exploited":false,"published_at":"2026-08-11T17:17:43.633+00:00","url":"https://junglewise.ai/threats/cve-2025-31938-intel-tdx-firmware-confidential-vm-escape"},{"cve":"CVE-2026-6726","cvss":7.9,"epss":0.0019,"slug":"cve-2026-6726-trusted-computing-group-tpm-2-0-reference-implementation-memory","title":"An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileg","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:34.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6726-trusted-computing-group-tpm-2-0-reference-implementation-memory"},{"cve":"CVE-2026-64561","cvss":8.8,"slug":"cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation","title":"Linux KVM x86 shadow MMU privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation"},{"cve":"CVE-2026-59309","cvss":9.8,"slug":"cve-2026-59309-vmware-vcenter-authentication-bypass-in-vmware-directory-service","title":"VMware vCenter authentication bypass in VMware Directory Service","severity":"critical","exploited":false,"published_at":"2026-07-30T13:16:53.87+00:00","url":"https://junglewise.ai/threats/cve-2026-59309-vmware-vcenter-authentication-bypass-in-vmware-directory-service"},{"cve":"CVE-2026-15810","cvss":8.7,"slug":"cve-2026-15810-google-cloud-looker-xss-leading-to-administrative-account","title":"Google Cloud Looker XSS leading to administrative account takeover","severity":"high","exploited":false,"published_at":"2026-07-24T12:16:47.543+00:00","url":"https://junglewise.ai/threats/cve-2026-15810-google-cloud-looker-xss-leading-to-administrative-account"},{"cve":"CVE-2026-12715","cvss":8.5,"slug":"cve-2026-12715-google-cloud-firebase-studio-missing-authorization-in","title":"Google Cloud Firebase Studio missing authorization in GetSignedGcsUrl RPC","severity":"high","exploited":false,"published_at":"2026-07-17T16:17:13.047+00:00","url":"https://junglewise.ai/threats/cve-2026-12715-google-cloud-firebase-studio-missing-authorization-in"},{"cve":"CVE-2026-14934","cvss":9.4,"slug":"cve-2026-14934-google-cloud-bigquery-and-dataform-auth-bypass-in-repository","title":"Google Cloud BigQuery and Dataform auth bypass in repository creation","severity":"high","exploited":false,"published_at":"2026-07-13T11:16:26.47+00:00","url":"https://junglewise.ai/threats/cve-2026-14934-google-cloud-bigquery-and-dataform-auth-bypass-in-repository"},{"slug":"google-cloud-developer-connect-privilege-escalation-aab426d7","title":"Google Cloud Developer Connect privilege escalation","severity":"info","exploited":false,"published_at":"2026-07-13T00:00:00+00:00","url":"https://junglewise.ai/threats/google-cloud-developer-connect-privilege-escalation-aab426d7"},{"cve":"CVE-2026-53359","cvss":7.8,"slug":"cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu","title":"Linux Kernel KVM shadow paging use-after-free in x86 MMU","severity":"high","exploited":false,"published_at":"2026-07-04T12:17:01.76+00:00","url":"https://junglewise.ai/threats/cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu"},{"cve":"CVE-2026-50195","cvss":3.1,"epss":0.003,"slug":"cve-2026-50195-containerd-image-tag-poisoning-in-cri-checkpoint-import","title":"containerd image tag poisoning in CRI checkpoint import","severity":"high","exploited":false,"published_at":"2026-07-01T19:16:53.333+00:00","url":"https://junglewise.ai/threats/cve-2026-50195-containerd-image-tag-poisoning-in-cri-checkpoint-import"},{"slug":"envoy-proxy-qpack-decoding-denial-of-service-in-http-3-95f03635","title":"Envoy Proxy QPACK decoding denial-of-service in HTTP/3","severity":"info","exploited":false,"published_at":"2026-06-29T00:00:00+00:00","url":"https://junglewise.ai/threats/envoy-proxy-qpack-decoding-denial-of-service-in-http-3-95f03635"},{"cve":"CVE-2026-47692","cvss":4.8,"slug":"cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch","title":"Envoy PROXY Protocol v2 request smuggling via TLV length mismatch","severity":"high","exploited":false,"published_at":"2026-06-26T18:16:59.22+00:00","url":"https://junglewise.ai/threats/cve-2026-47692-envoy-proxy-protocol-v2-request-smuggling-via-tlv-length-mismatch"},{"cve":"CVE-2025-0982","slug":"cve-2025-0982-google-application-integration-javascript-rce-via-rhino-engine","title":"Google Application Integration JavaScript RCE via Rhino engine","severity":"high","exploited":false,"published_at":"2026-06-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-0982-google-application-integration-javascript-rce-via-rhino-engine"},{"slug":"google-cloud-build-privilege-escalation-in-secret-manager-4fab4bda","title":"Google Cloud Build privilege escalation in Secret Manager","severity":"info","exploited":false,"published_at":"2026-06-24T00:00:00+00:00","url":"https://junglewise.ai/threats/google-cloud-build-privilege-escalation-in-secret-manager-4fab4bda"},{"cve":"CVE-2026-8934","cvss":6.9,"slug":"cve-2026-8934-google-cloud-console-missing-authorization-in-app-engine-graphql","title":"Google Cloud Console missing authorization in App Engine GraphQL API","severity":"high","exploited":false,"published_at":"2026-06-22T16:16:43.097+00:00","url":"https://junglewise.ai/threats/cve-2026-8934-google-cloud-console-missing-authorization-in-app-engine-graphql"},{"slug":"google-cloud-logging-log-sink-hijacking-via-bucket-recreation-0f6a7602","title":"Google Cloud Logging log sink hijacking via bucket recreation","severity":"info","exploited":false,"published_at":"2026-06-22T00:00:00+00:00","url":"https://junglewise.ai/threats/google-cloud-logging-log-sink-hijacking-via-bucket-recreation-0f6a7602"},{"cve":"CVE-2026-47774","cvss":7.5,"epss":0.0056,"slug":"cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification","title":"Envoy Proxy denial of service via HTTP/2 HPACK amplification","severity":"high","exploited":false,"published_at":"2026-06-17T18:18:02.643+00:00","url":"https://junglewise.ai/threats/cve-2026-47774-envoy-proxy-denial-of-service-via-http-2-hpack-amplification"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Google Chrome","slug":"chrome","vulnerabilities":2530,"url":"https://junglewise.ai/threats/technologies/chrome"},{"name":"Google Android","slug":"android","vulnerabilities":359,"url":"https://junglewise.ai/threats/technologies/android"},{"name":"Google Chrome for iOS","slug":"chrome-for-ios","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/chrome-for-ios"},{"name":"Google Chromium V8","slug":"chromium-v8","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/chromium-v8"},{"name":"Google Chromium","slug":"chromium","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/chromium"},{"name":"Google TensorFlow","slug":"tensorflow","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/tensorflow"},{"name":"Google Android Framework","slug":"android-framework","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/android-framework"},{"name":"Google Chrome for Android","slug":"chrome-for-android","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/chrome-for-android"},{"name":"Google ChromeOS","slug":"chromeos","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/chromeos"},{"name":"Google Pixel Bootloader","slug":"pixel-bootloader","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/pixel-bootloader"},{"name":"Google WebView","slug":"webview","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webview"},{"name":"Google A2ui\\","slug":"a2ui","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/a2ui"}],"technology":{"hub":true,"name":"Google Cloud Platform","slug":"google-cloud-platform","vendor":{"name":"Google","slug":"google","url":"https://junglewise.ai/threats/vendors/google"},"aliases":[],"homepage":"https://cloud.google.com","description":"Cloud computing platform providing computing, storage, and analytics services.","url":"https://junglewise.ai/threats/technologies/google-cloud-platform"},"most_severe":[{"cve":"CVE-2026-59309","cvss":9.8,"slug":"cve-2026-59309-vmware-vcenter-authentication-bypass-in-vmware-directory-service","title":"VMware vCenter authentication bypass in VMware Directory Service","severity":"critical","exploited":false,"published_at":"2026-07-30T13:16:53.87+00:00","url":"https://junglewise.ai/threats/cve-2026-59309-vmware-vcenter-authentication-bypass-in-vmware-directory-service"},{"cve":"CVE-2026-14934","cvss":9.4,"slug":"cve-2026-14934-google-cloud-bigquery-and-dataform-auth-bypass-in-repository","title":"Google Cloud BigQuery and Dataform auth bypass in repository creation","severity":"high","exploited":false,"published_at":"2026-07-13T11:16:26.47+00:00","url":"https://junglewise.ai/threats/cve-2026-14934-google-cloud-bigquery-and-dataform-auth-bypass-in-repository"},{"cve":"CVE-2026-2264","cvss":9.2,"slug":"cve-2026-2264-google-cloud-apigee-ssrf-in-setintegrationrequest-policy","title":"Google Cloud Apigee SSRF in SetIntegrationRequest policy","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:30.76+00:00","url":"https://junglewise.ai/threats/cve-2026-2264-google-cloud-apigee-ssrf-in-setintegrationrequest-policy"},{"cve":"CVE-2026-64561","cvss":8.8,"slug":"cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation","title":"Linux KVM x86 shadow MMU privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation"},{"cve":"CVE-2026-15810","cvss":8.7,"slug":"cve-2026-15810-google-cloud-looker-xss-leading-to-administrative-account","title":"Google Cloud Looker XSS leading to administrative account takeover","severity":"high","exploited":false,"published_at":"2026-07-24T12:16:47.543+00:00","url":"https://junglewise.ai/threats/cve-2026-15810-google-cloud-looker-xss-leading-to-administrative-account"},{"cve":"CVE-2026-12715","cvss":8.5,"slug":"cve-2026-12715-google-cloud-firebase-studio-missing-authorization-in","title":"Google Cloud Firebase Studio missing authorization in GetSignedGcsUrl RPC","severity":"high","exploited":false,"published_at":"2026-07-17T16:17:13.047+00:00","url":"https://junglewise.ai/threats/cve-2026-12715-google-cloud-firebase-studio-missing-authorization-in"},{"cve":"CVE-2026-6726","cvss":7.9,"epss":0.0019,"slug":"cve-2026-6726-trusted-computing-group-tpm-2-0-reference-implementation-memory","title":"An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileg","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:34.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6726-trusted-computing-group-tpm-2-0-reference-implementation-memory"},{"cve":"CVE-2026-46300","cvss":7.8,"epss":0.0005,"slug":"cve-2026-46300-linux-kernel-out-of-bounds-write-in-skbuff-coalescing","title":"Linux Kernel out-of-bounds write in skbuff coalescing","severity":"high","exploited":false,"published_at":"2026-05-23T12:17:02.66+00:00","url":"https://junglewise.ai/threats/cve-2026-46300-linux-kernel-out-of-bounds-write-in-skbuff-coalescing"},{"cve":"CVE-2026-53359","cvss":7.8,"slug":"cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu","title":"Linux Kernel KVM shadow paging use-after-free in x86 MMU","severity":"high","exploited":false,"published_at":"2026-07-04T12:17:01.76+00:00","url":"https://junglewise.ai/threats/cve-2026-53359-linux-kernel-kvm-shadow-paging-use-after-free-in-x86-mmu"},{"cve":"CVE-2026-34480","cvss":7.5,"epss":0.0119,"slug":"cve-2026-34480-apache-log4j-core-invalid-xml-output-in-xmllayout","title":"Apache Log4j Core invalid XML output in XmlLayout","severity":"high","exploited":false,"published_at":"2026-04-10T16:16:31.463+00:00","url":"https://junglewise.ai/threats/cve-2026-34480-apache-log4j-core-invalid-xml-output-in-xmllayout"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}