{"record":"Google Cloud Platform evidence record","url":"https://nexalign.io/vendors/google-cloud-platform","vendor":{"slug":"google-cloud-platform","name":"Google Cloud Platform","domain":"cloud.google.com","category":"cloud","categoryLabel":"Cloud and sovereign cloud"},"lastChecked":"2026-07-17T16:19:33.349Z","coverage":{"earliest":"2018-03-19T18:00:00.000Z","latest":"2026-07-14T06:46:40.277Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":55,"kindsOfSource":5,"attributedAdvisories":31,"knownExploited":0,"registerEntriesNotAttributable":9,"practitionerThreads":0,"independentItems":2,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":20,"latest":"2026-07-14T06:46:40.277Z"},{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":19,"latest":"2026-07-13T10:20:19.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":8,"latest":"2026-07-13T11:16:26.470Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":6,"latest":"2026-04-08T14:44:23.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":2,"latest":"2026-06-19T04:19:53.558Z"}],"advisories":{"shown":6,"total":31,"truncated":true,"fullList":"https://nexalign.io/vendors/google-cloud-platform/advisories","items":[{"id":"WID-SEC-2026-2297","description":"Affected products: Google Cloud Platform","severity":"high","cvss":9.9,"knownExploited":false,"date":"2026-07-14T06:46:40.277Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2297"]},{"id":"CVE-2026-14934","description":"A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th…","severity":"critical","cvss":9.4,"knownExploited":false,"date":"2026-07-13T11:16:26.470Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-14934","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43338"]},{"id":"CVE-2026-12879","description":"An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate…","severity":"medium","cvss":5.9,"knownExploited":false,"date":"2026-07-09T14:16:27.840Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-12879","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42584"]},{"id":"WID-SEC-2026-2009","description":"Affected products: Amazon Linux 2, Fedora Linux, SUSE openSUSE, Google Cloud Platform","severity":"high","cvss":8.8,"knownExploited":false,"date":"2026-07-02T09:05:53.871Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2009"]},{"id":"WID-SEC-2026-2087","description":"Affected products: Google Cloud Platform","severity":"high","cvss":8.7,"knownExploited":false,"date":"2026-06-26T11:11:32.108Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2087"]},{"id":"CVE-2026-4764","description":"A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges…","severity":"critical","cvss":9.4,"knownExploited":false,"date":"2026-06-11T12:16:31.620Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-4764","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36221"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Google Cloud Platform Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/strategic-cloud-platform-services/vendor/google/product/google-cloud-platform","date":null},{"title":"Google Cloud Platform - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Google_Cloud_Platform","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 9 register entries mention Google Cloud Platform without naming a product of Google Cloud Platform as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Google Cloud Platform was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}