Cloud and sovereign cloud

Google Cloud Platform advisories: every record the registers tie to its products

In one line

31 advisories are attributed to Google Cloud Platform products in this record, covering June 2020 to July 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 9 register entries mention Google Cloud Platform without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

31

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

4

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Google Cloud Platform, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

9 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

31 of the 31 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • WID-SEC-2026-2297highCVSS 9.9Jul 14, 2026

    Affected products: Google Cloud Platform

  • CVE-2026-14934criticalCVSS 9.4Jul 13, 2026

    A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th…

  • CVE-2026-12879mediumCVSS 5.9Jul 09, 2026

    An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate…

  • WID-SEC-2026-2009highCVSS 8.8Jul 02, 2026

    Affected products: Amazon Linux 2, Fedora Linux, SUSE openSUSE, Google Cloud Platform

  • WID-SEC-2026-2087highCVSS 8.7Jun 26, 2026

    Affected products: Google Cloud Platform

  • CVE-2026-4764criticalCVSS 9.4Jun 11, 2026

    A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges…

  • CVE-2026-48245mediumCVSS 5.3May 21, 2026

    Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository.

  • CVE-2026-48244mediumCVSS 5.3May 21, 2026

    Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository.

  • WID-SEC-2026-0474highCVSS 9.0Apr 24, 2026

    Affected products: Red Hat Enterprise Linux, Google Cloud Platform

  • CVE-2026-3259highCVSS 7.1Apr 23, 2026

    A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated…

  • WID-SEC-2026-0704mediumCVSS 7.5Apr 02, 2026

    Affected products: Amazon Linux 2, Red Hat Enterprise Linux, Google Cloud Platform

  • WID-SEC-2026-0541highCVSS 9.9Feb 27, 2026

    Affected products: Google Cloud Platform

  • CVE-2026-2473highCVSS 7.7Feb 20, 2026

    Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote…

  • WID-SEC-2026-0418mediumCVSS 7.1Feb 16, 2026

    Affected products: Google Cloud Platform

  • WID-SEC-2026-0122mediumCVSS 4.9Jan 15, 2026

    Affected products: Google Cloud Platform

  • WID-SEC-2025-2433mediumCVSS 7.5Jan 06, 2026

    Affected products: Amazon Linux 2, Google Cloud Platform

  • WID-SEC-2025-2766mediumCVSS 6.3Dec 10, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-2754highCVSS 8.8Dec 09, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-2661highCVSS 8.0Nov 25, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-2649highCVSS 9.8Nov 21, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-1962highCVSS 9.6Nov 11, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-1973highCVSS 8.5Sep 05, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-1945mediumCVSS 7.5Sep 03, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-1256lowCVSS 4.1Jun 10, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-1081highCVSS 9.4May 19, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-0601mediumCVSS 5.7Mar 20, 2025

    Affected products: Google Cloud Platform

  • WID-SEC-2025-0589mediumCVSS 7.5Mar 19, 2025

    Affected products: Google Cloud Platform

  • CVE-2024-12236mediumCVSS 6.8Dec 10, 2024

    A security issue exists in Vertex Gemini API for customers using VPC-SC.

  • CVE-2020-8933criticalCVSS 9.3Jun 22, 2020

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to…

  • CVE-2020-8907criticalCVSS 9.3Jun 22, 2020

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to…

  • CVE-2020-8903highCVSS 7.3Jun 22, 2020

    A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to…

Which registers contributed

RegisterOperated byEntriesLatest
CERT-Bund security advisoriesBSI, Federal Republic of Germany20Jul 14, 2026
European Vulnerability DatabaseENISA, European Union19Jul 13, 2026
National Vulnerability DatabaseNIST, United States Department of Commerce8Jul 13, 2026

The entry counts here are the raw register totals for Google Cloud Platform, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Google Cloud Platform have?

31 advisories in this record are tied by a register to a product of Google Cloud Platform. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Google Cloud Platform vulnerabilities being actively exploited?

None of the 31 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Google Cloud Platform than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 9 register entries name Google Cloud Platform without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Google Cloud Platform advisories on this page come from?

From CERT-Bund security advisories (BSI, Federal Republic of Germany); European Vulnerability Database (ENISA, European Union); National Vulnerability Database (NIST, United States Department of Commerce). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Google Cloud Platform is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Google Cloud Platform record, including sources and open questions

Google Cloud Platform vulnerabilities: all 31 advisories on record, with sources | DecisionOS by nexalign