<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:google-cloud-security-bulletins</id>
  <title>Google Cloud - Security Bulletins</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/google-cloud-security-bulletins.xml"/>
  <author>
    <name>Google Cloud Documentation</name>
  </author>
  <updated>2026-07-13T15:33:57.610697+00:00</updated>


  <entry>
    <title>GCP-2026-048</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-048</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-048"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-07-13</p><h3 class="hide-from-toc" data-text="Description" id="description" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets.</p>
<p>For instructions and more details, see the
           <a href="https://docs.cloud.google.com/developer-connect/docs/security-bulletins#gcp-2026-048">Developer Connect security bulletin</a>.
        </p>
</td>
<td>Medium</td>
<td></td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-047</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-047</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-047"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-07-13</p><h3 class="hide-from-toc" data-text="Description" id="description_1" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A Missing Authorization vulnerability was discovered in repositories
       in BigQuery, Dataform, and Colab Enterprise.</p>
<h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Google has already applied mitigations to all impacted products and services.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>During repository creation, an authenticated attacker could potentially escalate their permissions and perform cross-tenant repository takeover.</p>
</td>
<td>Critical</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14934">CVE-2026-14934</a><br/>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-046</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-046</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-046"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-07-06</p><h3 class="hide-from-toc" data-text="Description" id="description_2" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A virtualization vulnerability has been identified in the KVM x86 shadow paging and nested virtualization configurations. Because an attacker operating a virtual machine with nested virtualization could escape hypervisor boundary isolation to compromise the underlying physical host, any x86 virtual machine (whether nested or non-nested) hosted on an Intel-based server supporting nested virtualization is potentially exposed.</p>
<h4 data-text="What should I do?" id="what-should-i-do_1" tabindex="-1">What should I do?</h4>
<p>Google is deploying live hypervisor hotpatches across all managed Compute Engine host servers globally. No action is required for managed Compute Engine virtual machines or Google Kubernetes Engine clusters. Because remediation is performed transparently at the physical host hypervisor level, customer VM downtime, reboots, or manual upgrades are not required.</p>
<p>Customers operating self-managed virtualized environments or custom host hypervisors outside standard managed Compute Engine infrastructure should ensure their host Linux kernel is updated with the upstream patch as soon as it is made available by their operating system vendor.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_1" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>The vulnerability (CVE-2026-53359) exploits a use-after-free error in the x86 shadow paging and nested page table translation routines. Google has observed no evidence of active customer exploitation in production environments. Live patching and host-level monitoring have been implemented globally to mitigate risk and detect exploit attempts.</p>
</td>
<td>High/S0</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53359">CVE-2026-53359</a><br/>
        (Januscape)
      </td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-045</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-045</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-045"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-29</p><h3 class="hide-from-toc" data-text="Description" id="description_3" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was detected in Envoy Proxy where blocked QPACK
        decoding can cause a Denial-of-Service Attack against the HTTP/3 stack.</p>
<p>For instructions and more details, see the
          <a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-045">Cloud Service Mesh security bulletin</a>.</p></td>
<td>High</td>
<td>
<a href="https://github.com/envoyproxy/envoy/security/advisories/GHSA-p7c7-7c47-pwch">GHSA-p7c7-7c47-pwch</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-044</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-044</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-044"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-25</p><h3 class="hide-from-toc" data-text="Description" id="description_4" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was detected in Application Integration's JavaScript task, which was using the Rhino JavaScript engine. This only impacted tasks published before January 2025.</p>
<p>For details and instructions, see the
           <a href="https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-044">Application Integration security bulletin</a>.
        </p>
</td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2025-0982">CVE-2025-0982</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-043</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-043</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-043"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-24</p><h3 class="hide-from-toc" data-text="Description" id="description_5" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was found in Firebase Studio where the
        <code dir="ltr" translate="no">GetSignedGcsUrl</code> RPC allowed authenticated users to list
        buckets and download deployment source code of other tenants.</p>
<p>No action is required to mitigate this vulnerability as the fix has
        been deployed to the backend service.</p>
<p>As a precautionary measure, users who stored sensitive information,
        such as API keys (for example, <code dir="ltr" translate="no">GEMINI_API_KEY</code>), within
        their Firebase Studio workspace may choose to rotate these keys. For
        instructions, see the
        <a href="https://firebase.google.com/docs/studio/troubleshooting#rotate-gemini-key">Firebase Studio troubleshooting guide</a>.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12715">CVE-2026-12715</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-042</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-042</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-042"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-24</p><h3 class="hide-from-toc" data-text="Description" id="description_6" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A privilege escalation vulnerability was addressed in Cloud Build. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Cloud Build service agent (P4SA) credentials only. Cloud Build now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets.</p>
<p>For instructions and more details, see the
           <a href="https://docs.cloud.google.com/build/docs/security-bulletins#gcp-2026-042">Cloud Build security bulletin</a>.
        </p>
</td>
<td>Low</td>
<td></td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-041</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-041</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-041"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-24</p><h3 class="hide-from-toc" data-text="Description" id="description_7" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A recent security investigation was conducted regarding log4j vulnerabilities (CVE-2026-34480 and CVE-2026-34477) reported in Apigee Edge for Private Cloud. Google has determined that Apigee Edge for Private Cloud is <strong>not vulnerable</strong> to these CVEs. <strong>No customer action is required.</strong></p>
<p>For more information, see the
          <a href="https://docs.cloud.google.com/apigee/docs/security-bulletins/security-bulletins#gcp-2026-041">Apigee security bulletin</a>.
        </p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34480">CVE-2026-34480</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34477">CVE-2026-34477</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-040</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-040</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-040"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-23</p><h3 class="hide-from-toc" data-text="Description" id="description_8" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A series of vulnerabilities were discovered in Envoy Proxy.</p>
<p>For instructions and more details, see the
           <a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-039">Cloud Service Mesh security bulletin</a>.
        </p>
</td>
<td>Moderate to High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47692">CVE-2026-47692</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47207">CVE-2026-47207</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47205">CVE-2026-47205</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47220">CVE-2026-47220</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47221">CVE-2026-47221</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48044">CVE-2026-48044</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48090">CVE-2026-48090</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47778">CVE-2026-47778</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47204">CVE-2026-47204</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48497">CVE-2026-48497</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48706">CVE-2026-48706</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48743">CVE-2026-48743</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47775">CVE-2026-47775</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48042">CVE-2026-48042</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-039</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-039</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-039"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-06-22</p><h3 class="hide-from-toc" data-text="Description" id="description_9" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability in Cloud Logging could have allowed attackers to
         hijack log sink destinations by recreating the target Cloud Storage
         bucket in a project controlled by the attacker. This issue could have
         resulted in the continuous routing of sensitive logs to an unauthorized
         third party.</p>
<p>For more information, see the
        <a href="https://docs.cloud.google.com/stackdriver/security-bulletins#GCP-2026-039">Google Cloud Observability security bulletin</a>.</p></td>
<td>Medium</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-038</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-038</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-038"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-06-22</p><h3 class="hide-from-toc" data-text="Description" id="description_10" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was found in App Engine where the <code dir="ltr" translate="no">GetDashboardAppStats</code>
        GraphQL private API operation in the Google Cloud console leaked cross-tenant request logs.</p>
<p>No action is required. This vulnerability has been fixed.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8934">CVE-2026-8934</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-037</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-037</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-037"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-18</p><p><strong>Updated:</strong> 2026-06-20</p><h3 class="hide-from-toc" data-text="Description" id="description_11" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><strong>2026-06-20 Update:</strong> Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions 1.35 and 1.36. Patches for Ubuntu node images are still pending and in progress.</p><hr/>
<p><strong>2026-06-19 Update:</strong> Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions from 1.30 to 1.34. Patches for Ubuntu node images and for minor version 1.35 and 1.36 for Container-Optimized OS node images are in progress.</p><hr/>
<p>Multiple vulnerabilities have been discovered in containerd (the GKE container runtime). These vulnerabilities allow attackers with permissions to create pods to bypass Kubernetes security boundaries and perform host compromise, cache poisoning, and denial of service.</p>
<p>For instructions and more details, see the
          <a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-037">GKE security bulletin</a></p></td>
<td>Critical</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50195">CVE-2026-50195</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53488">CVE-2026-53488</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53492">CVE-2026-53492</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53489">CVE-2026-53489</a><br/>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-47262">CVE-2026-47262</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-036</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-036</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-036"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-06-09</p><h3 class="hide-from-toc" data-text="Description" id="description_12" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>ARM has announced CVE-2025-10263, an architectural issue affecting
        some Arm cores which lets an attacker bypass translation
        stages or GPT protections under certain conditions. This
        vulnerability lets an attacker at a lower exception level to
        write to memory owned by a higher exception level, thereby
        escalating privileges. This issue does not affect memory
        reads.</p>
<p>For more information, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-036">Compute Engine security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10263">CVE-2025-10263</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-035</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-035</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-035"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-06-08</p><h3 class="hide-from-toc" data-text="Description" id="description_13" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was found in Envoy where HTTP/2 downstream request
        processing allow an unauthenticated remote client to trigger excessive
        memory consumption, potentially resulting in OOM termination of the
        Envoy process and denial of service.</p>
<p>For instructions and more details, see the <a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">Cloud Service Mesh security bulletin</a>.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2026-47774">CVE-2026-47774</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-034</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-034</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-034"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-20</p><h3 class="hide-from-toc" data-text="Description" id="description_14" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was found in Apigee where the <code dir="ltr" translate="no">IntegrationRegion</code> parameter in the <code dir="ltr" translate="no">SetIntegrationRequest</code> policy lacks validation, allowing for Server-Side Request Forgery (SSRF) and service account token exfiltration. The issue arises when an attacker can control a flow variable used for <code dir="ltr" translate="no">IntegrationRegion</code>, leading to requests being sent to an attacker-controlled host with the service account token.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2264">CVE-2026-2264</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-033</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-033</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-033"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-14</p><h3 class="hide-from-toc" data-text="Description" id="description_15" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host.</p>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-033-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-033-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-033-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-033-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-033-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>Medium</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-46300">CVE-2026-46300</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-032</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-032</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-032"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-12</p><h3 class="hide-from-toc" data-text="Description" id="description_16" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>AMD has identified a hardware-level vulnerability in <strong>Zen 2 microarchitecture processors</strong> (including EPYC and Ryzen series) involving potential corruption within the <strong>micro-operation (OP) cache.</strong> Under specific conditions, this issue (AMD-SN-7052 / CVE-2025-54518) could lead to security boundary bypasses or unauthorized data access.<br/>We have deployed fixes across Google infrastructure to mitigate these issues.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-032">
          Compute Engine security bulletin</a>.</p>
</td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2025-54518">CVE-2025-54518</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-031</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-031</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-031"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-12</p><h3 class="hide-from-toc" data-text="Description" id="description_17" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Researchers discovered a vulnerability in AMD firmware that, due to missing protection, could allow a malicious hypervisor to execute arbitrary code on the AMD Secure Processor (ASP). This allows for the escalation of Memory Mapped I/O (MMIO) read and write permissions, which compromises the confidentiality and integrity of SEV-SNP guests.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-031">
          Compute Engine security bulletin</a>.</p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61971">CVE-2025-61971</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61972">CVE-2025-61972</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36315">CVE-2024-36315</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-030</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-030</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-030"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-11</p><p><strong>Updated:</strong> 2026-06-24</p><h3 class="hide-from-toc" data-text="Description" id="description_18" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><strong>2026-06-24 Update:</strong> Added patch versions for GKE.</p><hr/>
<p><strong>2026-05-20 Update:</strong> Added CVE-2026-43500 and added CVE IDs to exploit paths.</p><hr/>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
          </p><ul>
<li>CVE-2026-43284</li>
<li>CVE-2026-43500</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-030-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-030-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-030-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-030-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-030-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43284">CVE-2026-43284</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-029</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-029</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-029"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-07</p><h3 class="hide-from-toc" data-text="Description" id="description_19" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software. These older certificates begin expiring in June 2026. Devices that haven't received the newer 2023 certificates will continue to start and operate normally, and standard Windows updates will continue to install. However, these devices will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot-level vulnerabilities. Also, Secure Boot certificate expirations starting in June 2026 affect Linux systems that use Secure Boot.</p>
<h4 data-text="What should I do?" id="what-should-i-do_2" tabindex="-1">What should I do?</h4>
<p>Google recommends that customers update their Windows VMs by taking appropriate actions as recommended by Microsoft. Distributions like Ubuntu, Red Hat, and Fedora are already working to provide updated packages signed with the new 2023 key. Refer also to the <a class="external" href="https://knowledge.broadcom.com/external/article/423893/secure-boot-certificate-expirations-and.html">Broadcom documentation</a> to resolve errors and warnings in VMware virtual machines as Secure Boot certificates approach expiration. After June 2026, systems lacking the 2023 certificate updates may experience failures during new operating system installations or while updating the existing bootloader firmware.</p>
</td>
<td>Informational</td>
<td>
<a class="external" href="https://knowledge.broadcom.com/external/article/423893/secure-boot-certificate-expirations-and.html">Broadcom KB 423893</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-028</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-028</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-028"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-05</p><p><strong>Updated:</strong> 2026-05-27</p><h3 class="hide-from-toc" data-text="Description" id="description_20" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a>, also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access. Disclosed in late April 2026, it stems from a logic flaw in the kernel's cryptographic subsystem (algif_aead) introduced in 2017.</p>
<h4 data-text="What should I do?" id="what-should-i-do_3" tabindex="-1">What should I do?</h4>
<p>Google recommends that customers protect their Linux Guest VMs by updating the kernel on all Linux VMs. Major distributions have released or are rolling out fixes.</p>
</td>
<td>High</td>
<td>
<a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-027</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-027</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-027"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-01</p><h3 class="hide-from-toc" data-text="Description" id="description_21" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS nodes:
          </p><ul>
<li>CVE-2026-23351</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-027-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-027-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-027-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-027-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-027-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23351">CVE-2026-23351</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-026</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-026</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-026"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-30</p><p><strong>Updated:</strong> 2026-05-04</p><h3 class="hide-from-toc" data-text="Description" id="description_22" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><strong>2026-05-04 Update:</strong> Added patch versions for GKE.</p><hr/>
<p>A vulnerability in the Linux kernel (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31431">CVE-2026-31431</a>) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape.
        </p>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-026-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-026-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-026-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-026-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-026-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31431">CVE-2026-31431</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-025</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-025</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-025"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-30</p><h3 class="hide-from-toc" data-text="Description" id="description_23" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS nodes:
          </p><ul>
<li>CVE-2026-23274</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-025-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-025-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-025-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-025-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-025-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23274">CVE-2026-23274</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-024</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-024</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-024"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-28</p><h3 class="hide-from-toc" data-text="Description" id="description_24" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
          </p><ul>
<li>CVE-2025-38248</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-024-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-024-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-024-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-024-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-024-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-38248">CVE-2025-38248</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-023</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-023</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-023"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-28</p><p><strong>Updated:</strong> 2026-05-07</p><h3 class="hide-from-toc" data-text="Description" id="description_25" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><strong>2026-05-07 Update:</strong> Added patch versions for Ubuntu
        node pools on GKE</p><hr/>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS nodes:
          </p><ul>
<li>CVE-2026-23074</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-023-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-023-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-023-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-023-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-023-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23074">CVE-2026-23074</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-022</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-022</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-022"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-16</p><h3 class="hide-from-toc" data-text="Description" id="description_26" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS nodes:
          </p><ul>
<li>CVE-2026-23209</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-022-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-022-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-022-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-022-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-022-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23209">CVE-2026-23209</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-021</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-021</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-021"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-04-14</p><h3 class="hide-from-toc" data-text="Description" id="description_27" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
          AMD reported a vulnerability in its firmware that could have allowed
          a malicious hypervisor to direct the IOMMU to write into the guest
          memory of AMD SEV-SNP enabled instances, compromising guest data
          integrity. Google rolled out a mitigation to vulnerable
          Confidential VM instances with AMD SEV-SNP enabled.
        </p>
<h4 data-text="What should I do?" id="what-should-i-do_4" tabindex="-1">What should I do?</h4>
<p>
          No customer action is needed. The mitigation has already been
          applied to Confidential VM instances with AMD SEV-SNP
          enabled.
        </p>
<p>
          For more information, see AMD advisory
          <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3016.html">
            AMD-SB-3016</a>.
        </p>
</td>
<td>Medium</td>
<td>
<p style="white-space:nowrap">
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20585">CVE-2023-20585</a>
</p>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-020</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-020</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-020"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-14</p><h3 class="hide-from-toc" data-text="Description" id="description_28" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The following vulnerabilities were discovered in the Linux kernel that can lead
          to a privilege escalation on Container-Optimized OS nodes:
          </p><ul>
<li>CVE-2026-23231</li>
</ul>
<p>For instructions and more details, see the following bulletins:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020-gke">GKE security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020-gdcvmware">GDC software for VMware security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020-gkeaws">GKE on AWS security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020-gkeazure">GKE on Azure security bulletin</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020-gdcbm">GDC software for bare metal security bulletin</a></li>
</ul>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23231">CVE-2026-23231</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-019</title>
    <id>tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-019</id>
    <updated>2026-07-13T15:33:57.610697+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/support/bulletins/index#gcp-2026-019"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-14</p><h3 class="hide-from-toc" data-text="Description" id="description_29" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Researchers discovered a vulnerability in AMD firmware that could allow a malicious hypervisor to alter BIOS settings and Memory Mapped I/O (MMIO) routing configurations, compromising the confidentiality and integrity of Confidential VMs with AMD SEV-SNP guests.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-019">
          Compute Engine security bulletin</a>.</p>
</td>
<td>Medium</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-54510">CVE-2025-54510</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
