Advisories covering CVEs and security issues affecting Google Cloud Platform services: GKE, Cloud IAM, Security Command Center, Cloud Armor, and the broader GCP service portfolio. Each advisory includes severity, attack vector, and a recommended action for architects managing GCP workloads.

Looking for cross-cloud security guidance? Our practitioner guides cover the controls and frameworks that apply across GCP, AWS, and Azure:

GCP CVE-2024-6387: OpenSSH RCE Bug Hits Compute Engine

Critical OpenSSH vulnerability CVE-2024-6387 allows unauthenticated root RCE on GCP Compute Engine VMs. Patch now or restrict SSH exposure immediately.

🔴 Critical  |  GCP Compute Engine Security Bulletins  |  11 Aug 2026

GCP Log4Shell CVE-2021-44228: M4CE Patch Guidance

Google Cloud bulletin GCP-2021-026 covers Log4Shell (CVE-2021-44228) affecting Migrate for Compute Engine. Learn what action to take now.

🔴 Critical  |  GCP Compute Engine Security Bulletins  |  11 Aug 2026

GCP COS Privilege Escalation: CVE-2026-23268 CrackArmor

CVE-2026-23268 (CrackArmor) enables Linux kernel privilege escalation on GCP Container-Optimized OS nodes. Upgrade to cos-125-19216-220-57 immediately.

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP CVE-2021-3156: sudo Privilege Escalation in Compute Engi

CVE-2021-3156 sudo vulnerability allows local privilege escalation to root on GCP Compute Engine Linux VMs. Patch guest OS images immediately.

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP CVE-2023-1017 & CVE-2023-1018: vTPM Flaws Fixed

Two TPM 2.0 vulnerabilities (CVE-2023-1017, CVE-2023-1018) affected GCP Compute Engine VMs, risking code execution and data leakage. Google auto-patched al

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP CVE-2024-3094: xz-utils Backdoor & Compute Engine

GCP Compute Engine public images are unaffected by the xz-utils backdoor CVE-2024-3094, but custom images on Fedora 41, Debian testing, or openSUSE Tumblew

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP CVE-2024-45332: Intel Side-Channel Flaw Patched

Google has patched CVE-2024-45332, an Intel side-channel vulnerability affecting Cascade Lake, Ice Lake, Sapphire Rapids and Emerald Rapids CPUs on Google

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP CVE-2026-6726: TPM 2.0 Attestation Key Flaw

CVE-2026-6726 affects TPM 2.0 reference code on GCP Compute Engine, allowing privileged attackers to forge attestation keys. No customer action needed — Go

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP Intel CPU Flaws CVE-2025-21090 & CVE-2025-22840

Two Intel CPU vulnerabilities affect multiple GCP VM families. CVE-2025-21090 lets unprivileged users crash host machines. Google patches automatically — n

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP Intel L1TF CPU Flaw Update: CVE-2018-3646

Google Cloud patches a resurfaced Intel L1 cache vulnerability (CVE-2018-3646) affecting Skylake, Broadwell & Haswell CPUs — what GCP architects need to kn

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP-2023-44: AMD EPYC CPU Vulnerabilities in Google Cloud

Google has patched 11 AMD EPYC CPU vulnerabilities (including CVE-2023-20533) across GCP infrastructure. No customer action required for Compute Engine.

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GCP-2025-024: Intel Speculative Execution Flaw on GCP

Google has patched GCP infrastructure against an Intel Cascade Lake and Ice Lake speculative execution vulnerability. No customer action needed yet, but OS

🟠 High  |  GCP Compute Engine Security Bulletins  |  11 Aug 2025

GKE containerd Flaws CVE-2026-50195 & More

Multiple containerd vulnerabilities in GKE allow Pod-privileged attackers to compromise hosts, poison caches, and cause DoS. Patch GKE nodes now.

🟠 High  |  GCP GKE Security Bulletins  |  18 Jun 2025

GCP CVE-2025-0647: Arm TLB Flaw in Compute Engine VMs

CVE-2025-0647 affects GCP Compute Engine Arm VMs (C4A, A4X). A TLB invalidation flaw could expose sensitive data. Google has already patched the issue.

🟡 Medium  |  GCP Compute Engine Security Bulletins  |  11 Aug 2024

GCP Shielded VM vTPM Flaw CVE-2025-2884 | GCP-2025-031

CVE-2025-2884 affects GCP Shielded VMs with vTPM, allowing local attackers to read sensitive TPM data. Google patches automatically — no customer action re

🟡 Medium  |  GCP Compute Engine Security Bulletins  |  11 Aug 2024

GCP UEFI Secure Boot Bypass: CVE-2022-36763/64/65

Google patches three TianoCore EDK II UEFI vulnerabilities in Compute Engine that could bypass Secure Boot, including on Shielded VMs. No action required.

🟡 Medium  |  GCP Compute Engine Security Bulletins  |  11 Aug 2024

GCP-2025-058: AMD Zen 5 RDSEED Flaw on Compute Engine

AMD Zen 5 Turin processors have a flaw causing 16/32-bit RDSEED to silently fail, risking weak cryptographic randomness in GCP Compute Engine workloads.

🟡 Medium  |  GCP Compute Engine Security Bulletins  |  11 Aug 2024

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options