Security bulletins
From time to time, we might release security bulletins related to Google Cloud VMware Engine. All security bulletins for VMware Engine are described here.
Use this XML feed to subscribe to security bulletins for this page.
![]()
GCP-2026-050
Published: 2026-07-29
Description
| Description | Severity | Notes |
|---|---|---|
|
Per advisory VMSA-2026-0006, multiple vulnerabilities in VMware ESXi, and vCenter were privately reported to Broadcom. We are in the process of applying the necessary patches supplied by Broadcom. There are no known workarounds for these reported vulnerabilities. Once patched, your VMware Engine deployments should be running vCenter and ESXi 8.0 U3k. What should I do?Google recommends customers to monitor their workloads on VMware Engine for any unusual activities. |
Critical |
|
GCP-2026-029
Published: 2026-05-07
Description
| Description | Severity | Notes |
|---|---|---|
|
Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software. These older certificates begin expiring in June 2026. Devices that haven't received the newer 2023 certificates will continue to start and operate normally, and standard Windows updates will continue to install. However, these devices will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot-level vulnerabilities. Also, Secure Boot certificate expirations starting in June 2026 affect Linux systems that use Secure Boot. What should I do?Google recommends that customers update their Windows VMs by taking appropriate actions as recommended by Microsoft. Distributions like Ubuntu, Red Hat, and Fedora are already working to provide updated packages signed with the new 2023 key. Refer also to the Broadcom documentation to resolve errors and warnings in VMware virtual machines as Secure Boot certificates approach expiration. After June 2026, systems lacking the 2023 certificate updates may experience failures during new operating system installations or while updating the existing bootloader firmware. |
Informational | Broadcom KB 423893 |
GCP-2026-028
Published: 2026-05-05
Updated: 2026-05-27
Description
| Description | Severity | Notes |
|---|---|---|
|
CVE-2026-31431, also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access. Disclosed in late April 2026, it stems from a logic flaw in the kernel's cryptographic subsystem (algif_aead) introduced in 2017. What should I do?Google recommends that customers protect their Linux Guest VMs by updating the kernel on all Linux VMs. Major distributions have released or are rolling out fixes. |
High | CVE-2026-31431 |
GCP-2025-054
Published: 2025-10-14
Description
| Description | Severity | Notes |
|---|---|---|
|
Per VMware security advisory VMSA-2025-0015, multiple vulnerabilities in VMware Aria Operations and VMware Tools were privately reported to Broadcom. Patches are available to remediate these vulnerabilities in affected Broadcom products. What should I do? We recommend upgrading to VMware Aria Automation 8.18.5 and VMware Tools 13.0.5. |
Important |