Google Cloud
First CVE: Aug 25, 2025Active for: 1 year
38
CVEs Published
More CVEs Published than 51% of tracked CNAs
19.0
Avg CVEs / Year
More Avg CVEs / Year than 66% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Google Cloud over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2025
10 months ago
Most Recent CVE
Jul 24, 2026
0 days ago
Top CVEs
All CVEs published by Google Cloud as a CNA, regardless of affected vendor or product.
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4810CRITICAL A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run | Apr 13, 2026 | 9.3 | 44 | NO | YES |
CVE-2026-14934CRITICAL A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May | Jul 13, 2026 | 9.4 | 41 | NO | NO |
CVE-2026-12537HIGH Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) | Jun 24, 2026 | 7.8 | 39 | NO | NO |
CVE-2026-2031CRITICAL An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to | May 15, 2026 | 10.0 | 39 | NO | NO |
CVE-2026-4764CRITICAL A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate pr | Jun 11, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-12715HIGH Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and acc | Jul 17, 2026 | 8.5 | 34 | NO | NO |
CVE-2025-9118CRITICAL A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories vi | Aug 25, 2025 | 10.0 | 34 | NO | NO |
CVE-2026-2264CRITICAL A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access | May 26, 2026 | 9.2 | 33 | NO | NO |
CVE-2026-7428CRITICAL Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could | May 12, 2026 | 9.2 | 33 | NO | NO |
CVE-2026-1727CRITICAL The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized | Feb 6, 2026 | 9.1 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA38 CVEs
13%
58%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCriticalUnknown
Attack Vector
Local1 (2.6%)
Network36 (94.7%)
Unknown1 (2.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (81.6%)
High6 (15.8%)
Unknown1 (2.6%)
User Interaction
None29 (76.3%)
Unknown1 (2.6%)
Required2 (5.3%)
Privileges Required
Low18 (47.4%)
High5 (13.2%)
None14 (36.8%)
Unknown1 (2.6%)
Exploit Exposure
Signals from CVEs in this cna scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.6% of CVEs· 88th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Google Cloud as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Google Cloud as a CNA — matched by CVE ID, not by organization name.