VulnSea

Google Cloud has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.9 (high), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.9
Publish → KEV
Last 90 days
4 prev 0

Products

  • Agent Development Kit (ADK) for Python 1
  • Gemini CLI 1
  • Gemini Enterprise Agent Platform App Builder 1
  • Gemini Enterprise Agent Platform SDK for Python 1
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Google Cloud vulnerabilities

CVEs affecting Google Cloud, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-19407High· 7.7
1w ago

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

TwilightGoogle Cloud · Gemini Enterprise Agent Platform SDK for PythonEPSS 0.52%via NVD
CVE-2026-19486High· 8.7
1w ago

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

TwilightGoogle Cloud · Gemini Enterprise Agent Platform App BuilderEPSS 0.25%via NVD
CVE-2026-13745Critical· 9.2
1w ago

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

MidnightGoogle Cloud · Gemini CLIEPSS 0.30%via NVD
CVE-2026-79696Critical· 10.0
1w ago

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote att…

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote att…

MidnightGoogle Cloud · Agent Development Kit (ADK) for PythonEPSS 0.44%via NVD
Google Cloud vulnerabilities (CVEs) · VulnSea