Vulnerabilities · 171 days ago

Google Cloud warns of kernel, Envoy, and Vertex AI flaws

Google Cloud published security bulletins for multiple products. Several Linux kernel bugs can lead to privilege escalation on Container‑Optimized OS nodes. The company also disclosed multiple Envoy and Istio vulnerabilities and a Vertex AI predictable‑bucket naming flaw that can enable cross‑tenant remote code execution, model theft, and poisoning (CVE‑2026‑2473). Google added patch/version notes for Ubuntu nodes with GKE and says no customer action is needed to mitigate the Vertex AI issue.

CVEs in this update

331 CVEs

Across react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, and related packages.

18 critical · 169 high · 117 medium · 9 low

20 in CISA KEV · 121 with EPSS above 1%

21 with functional or packaged public exploit code

Highest severity: CVE-2025-55182 · 10.0 CRITICAL

Highest EPSS: CVE-2021-22005 · 100%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-01

Editions

Related stories