« All news

AlertCritical· Updated on

Google fixes two critical vulnerabilities in Cloud Application Integration with no customer action required

Google has published two security bulletins detailing critical vulnerabilities CVE-2026-19759 and CVE-2026-81867 in Cloud Application Integration. Both allowed authenticated users to run code or privileged internal calls, and both were already fixed on the platform in June 2026.

What happened

On 28 September 2026, Google published bulletins GCP-2026-064 and GCP-2026-065, documenting two critical-severity flaws in Google Cloud Application Integration, the managed integration service on Google Cloud Platform. Both carry a CVSS score of 9.4 out of 10.

CVE-2026-19759 is an incorrect authorization flaw in task configuration, affecting versions prior to 17 June 2026. According to Google's advisory, it allowed an authenticated Google Cloud user to leverage an internal-only task type to execute arbitrary internal RPCs from inside Google's production network under a privileged identity.

CVE-2026-81867 is a deserialization of untrusted data flaw in the JavaScript Task, affecting versions prior to 28 June 2026. An authenticated user with standard permissions could bypass parameter guards with a specially crafted script and run arbitrary code on shared production servers.

Who is affected

The issues affect organisations using Application Integration on Google Cloud Platform. Because this is a managed cloud service, the fix has been applied on Google's side: there is no version for customers to install and nothing to download.

Google states explicitly in both bulletins that no customer action is required, as the flaws were remediated on 17 June 2026 (CVE-2026-19759) and 28 June 2026 (CVE-2026-81867), that is, months before the advisories were published.

Exploitation status

Neither vulnerability appears in CISA's KEV catalogue of actively exploited flaws. FIRST's EPSS estimates are low: a 0.2% chance of exploitation in the next 30 days for CVE-2026-19759 and 0.4% for CVE-2026-81867.

These figures reflect the current situation, and with the service already fixed the residual risk to customers is limited. Even so, the 9.4 CVSS score shows how serious these flaws were before patching: privileged access to shared infrastructure with high impact on confidentiality, integrity and availability, including beyond the boundaries of the service itself.

What to do

There is nothing to patch, but a few housekeeping and governance checks are worthwhile:

Context

In the same batch of advisories, Google published bulletin GCP-2026-066, describing a high-severity confused deputy flaw in the Email Task component (CVE-2026-81375), fixed on 30 June 2026 and likewise requiring no customer action.

The case illustrates a familiar pattern in the SaaS model: the provider fixes first and discloses later. For IT leaders, the value of these bulletins lies less in immediate action and more in traceability, third-party risk management and documented evidence for audits.

Sources

Affected technologies

Google Cloud Application IntegrationGoogle Cloud Platform

Vulnerabilities (2)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-19759Critical (9.4)—9/28/2026Awaiting Analysis
CVE-2026-81867Critical (9.4)—9/28/2026Awaiting Analysis

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.