🟠 High  |  Source: GCP Compute Engine Security Bulletins


A vulnerability (CVE-2026-6726) in the Trusted Computing Group’s TPM 2.0 reference implementation affects all published revisions of the code, including versions used in GCP Compute Engine. A privileged local attacker could exploit this to obtain credentials from a TPM-aware Certificate Authority for a falsified TPM key, enabling fraudulent hardware attestations. Google has confirmed no customer action is required, as updates will be applied automatically during standard maintenance windows.

Security Architect’s Take: No immediate action is required for GCP Compute Engine workloads, as Google is patching systems automatically. However, architects relying on TPM-based attestation in hybrid or multi-cloud environments should audit whether on-premises or third-party systems running the affected TPM 2.0 reference implementation (v1.16–v1.84) also require patching, particularly where DevID, Attestation Keys, or TLS authentication keys are in use.

Original advisory: GCP-2026-054