<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins</id>
  <title>Google Cloud VMware Engine - Security Bulletins</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/google-cloud-vmware-engine-security-bulletins.xml"/>
  <author>
    <name>Google Cloud Documentation</name>
  </author>
  <updated>2026-07-29T17:07:38.222315+00:00</updated>


  <entry>
    <title>GCP-2026-050</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2026-050</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2026-050"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-07-29</p><h3 class="hide-from-toc" data-text="Description" id="description" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per advisory VMSA-2026-0006, multiple vulnerabilities in VMware ESXi, and vCenter were privately reported to Broadcom. We are in the process of applying the necessary patches supplied by Broadcom. There are no known workarounds for these reported vulnerabilities.</p>
<p>Once patched, your VMware Engine deployments should be running vCenter and ESXi 8.0 U3k.</p>
<h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4>
<p>Google recommends customers to monitor their workloads on VMware Engine for any unusual activities.</p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017">VMSA-2026-0006</a></li>
<li>CVE-2026-59309</li>
<li>CVE-2026-59310</li>
<li>CVE-2026-47876</li>
<li>CVE-2026-41703</li>
<li>CVE-2026-41709</li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-029</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2026-029</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2026-029"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-05-07</p><h3 class="hide-from-toc" data-text="Description" id="description_1" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software. These older certificates begin expiring in June 2026. Devices that haven't received the newer 2023 certificates will continue to start and operate normally, and standard Windows updates will continue to install. However, these devices will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot-level vulnerabilities. Also, Secure Boot certificate expirations starting in June 2026 affect Linux systems that use Secure Boot.</p>
<h4 data-text="What should I do?" id="what-should-i-do_1" tabindex="-1">What should I do?</h4>
<p>Google recommends that customers update their Windows VMs by taking appropriate actions as recommended by Microsoft. Distributions like Ubuntu, Red Hat, and Fedora are already working to provide updated packages signed with the new 2023 key. Refer also to the <a href="https://knowledge.broadcom.com/external/article/423893/secure-boot-certificate-expirations-and.html">Broadcom documentation</a> to resolve errors and warnings in VMware virtual machines as Secure Boot certificates approach expiration. After June 2026, systems lacking the 2023 certificate updates may experience failures during new operating system installations or while updating the existing bootloader firmware.</p>
</td>
<td>Informational</td>
<td>
<a href="https://knowledge.broadcom.com/external/article/423893/secure-boot-certificate-expirations-and.html">Broadcom KB 423893</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-028</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2026-028</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2026-028"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-05-05</p><p><strong>Updated:</strong> 2026-05-27</p><h3 class="hide-from-toc" data-text="Description" id="description_2" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a>, also known as "Copy Fail," is a high-severity local privilege escalation (LPE) vulnerability in the Linux kernel that allows an unprivileged user to gain root access. Disclosed in late April 2026, it stems from a logic flaw in the kernel's cryptographic subsystem (algif_aead) introduced in 2017.</p>
<h4 data-text="What should I do?" id="what-should-i-do_2" tabindex="-1">What should I do?</h4>
<p>Google recommends that customers protect their Linux Guest VMs by updating the kernel on all Linux VMs. Major distributions have released or are rolling out fixes.</p>
</td>
<td>High</td>
<td>
<a href="https://knowledge.broadcom.com/external/article?articleNumber=439189">CVE-2026-31431</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-054</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-054</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-054"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2025-10-14</p><h3 class="hide-from-toc" data-text="Description" id="description_3" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per VMware security advisory <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149">VMSA-2025-0015</a>, multiple vulnerabilities in VMware Aria Operations and VMware Tools were privately reported to Broadcom. Patches are available to remediate these vulnerabilities in affected Broadcom products.</p>
<p><strong>What should I do?</strong></p>
<p>We recommend upgrading to VMware Aria Automation 8.18.5 and VMware Tools 13.0.5.</p></td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149">VMSA-2025-0015</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41244">CVE-2025-41244</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41245">CVE-2025-41245</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41246">CVE-2025-41246</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-040</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-040</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-040"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-07-15</p><h3 class="hide-from-toc" data-text="Description" id="description_4" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per advisory VMSA-2025-0013, multiple vulnerabilities in VMware ESXi were privately reported to Broadcom.</p>
<p>We've either already patched these vulnerabilities or are in the process of applying the necessary patches supplied by Broadcom. There are no known workarounds for these reported vulnerabilities.</p>
<p>Once patched, your VMware Engine deployments should be running ESXi 7.0U3w or ESXi 8.0U3f or greater.</p>
<h4 data-text="What should I do?" id="what-should-i-do_3" tabindex="-1">What should I do?</h4>
<p>Google recommends customers to monitor their workloads on VMware Engine for any unusual activities.</p>
</td>
<td>Medium to Critical</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877">VMSA-2025-0013</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41236">CVE-2025-41236</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41237">CVE-2025-41237</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41238">CVE-2025-41238</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41239">CVE-2025-41239</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-030</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-030</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-030"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-23</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598">VMSA-2024-0017</a>, an SQL-injection vulnerability in VMware Aria Automation was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.</p>
<h4 data-text="What should I do?" id="what-should-i-do_4" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Automation KB325790.
       </p>
</td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598">VMSA-2024-0017</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22280">CVE-2024-22280</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-029</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-029</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-029"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-23</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25541">VMSA-2025-0006</a>, a local privilege escalation vulnerability in VMware Aria Operations was responsibly reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.</p>
<h4 data-text="What should I do?" id="what-should-i-do_5" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Operations 8.18 HF5.
       </p>
</td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25541">VMSA-2025-0006</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22231">CVE-2025-22231</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-028</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-028</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-028"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-23</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329">VMSA-2025-0003</a>, multiple vulnerabilities in VMware Aria Operations for logs and VMware Aria Operations were privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.</p>
<h4 data-text="What should I do?" id="what-should-i-do_6" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Operations for Logs 8.18.3 and VMware Aria Operations to 8.18.3.
       </p>
</td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329">VMSA-2025-0003</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22218">CVE-2025-22218</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22219">CVE-2025-22219</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22220">CVE-2025-22220</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22221">CVE-2025-22221</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22222">CVE-2025-22222</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-026</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-026</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-026"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-15</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25711">VMSA-2025-0008</a>, a DOM based Cross-Site Scripting (XSS) vulnerability in VMware Aria Automation was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.</p>
<h4 data-text="What should I do?" id="what-should-i-do_7" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Automation 8.18.1 patch 2.
       </p>
</td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25711">VMSA-2025-0008</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22249">CVE-2025-22249</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-011</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-011</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-011"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-03-06</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       VMware disclosed multiple vulnerabilities in <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390?utm_campaign=VCF_FY25_VCF_Security-Alert-VMSA-2025-0004_MKT_EM_2938&amp;utm_content=VCF_FY25_VCF_Security-Alert_2938_VMSA-2025-0004_MKT_TRANS_EM_5308&amp;utm_medium=email&amp;utm_source=eloqua">VMSA-2025-0004</a> that impact ESXi components deployed in customer environments.</p>
<h4 data-text="VMware Engine impact" id="impact" tabindex="-1">VMware Engine impact</h4>
<p>Your private clouds are either already patched or are in the process of being updated to address the security vulnerability. As part of the VMware Engine service, all customers get dedicated bare metal hosts with local attached disks that are physically isolated from other hardware. This means that the vulnerability is scoped to guest VMs within your specific private cloud only.</p>
<p>Your private clouds will be updated to 7.0u3s Build number 24534642. This is equivalent to 7.0U3s: Build number 24585291.</p>
<h4 data-text="What should I do?" id="what-should-i-do_8" tabindex="-1">What should I do?</h4>
<p>
       Follow instructions from Broadcom and your security vendors regarding this vulnerability.
       </p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390?utm_campaign=VCF_FY25_VCF_Security-Alert-VMSA-2025-0004_MKT_EM_2938&amp;utm_content=VCF_FY25_VCF_Security-Alert_2938_VMSA-2025-0004_MKT_TRANS_EM_5308&amp;utm_medium=email&amp;utm_source=eloqua">VMSA-2025-0004</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22224">CVE-2025-22224</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22225">CVE-2025-22225</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22226">CVE-2025-22226</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-004</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2025-004</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2025-004"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-01-16</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory VMSA-2025-0001, a server-side request forgery (SSRF) vulnerability in VMware Aria Automation was responsibly reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.</p>
<h4 data-text="What should I do?" id="what-should-i-do_9" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Automation 8.18.2 HF.
       </p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25312">VMSA-2025-0001</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22215">CVE-2025-22215</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-064</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-064</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-064"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-12-10</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory VMSA-2024-0022, multiple vulnerabilities in VMware Aria Operations were responsibly reported to VMware. Updates are available to remediate these vulnerabilities in the affected VMware product.</p>
<h4 data-text="What should I do?" id="what-should-i-do_10" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware Aria Operations 8.18.2.
       </p>
</td>
<td>Important</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199">VMSA-2024-0022</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38830">CVE-2024-38830</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38831">CVE-2024-38831</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38832">CVE-2024-38832</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38833">CVE-2024-38833</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38834">CVE-2024-38834</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-060</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-060</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-060"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-10-17</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory VMSA-2024-0020, multiple vulnerabilities in VMware NSX were responsibly reported to VMware.</p>
<p>The version NSX-T running on your VMware Engine environment is not impacted by CVE-2024-38815, CVE-2024-38818, or CVE-2024-38817.</p>
<h4 data-text="What should I do?" id="what-should-i-do_11" tabindex="-1">What should I do?</h4>
<p>
       Because VMware Engine clusters are not affected by this vulnerability, no further action is required.</p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25047">VMSA-2024-0020</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38215">CVE-2024-38815</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38217">CVE-2024-38817</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38218">CVE-2024-38818</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-059</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-059</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-059"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-10-16</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       Per VMware security advisory VMSA-2024-0021, an authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware.</p>
<p>We have applied the mitigation approved by VMware to address this vulnerability. This fix addresses a security vulnerability described in CVE-2024-38814. The image versions running in your VMware Engine private cloud don't reflect any change at this time to indicate the changes applied. Appropriate mitigations have been installed and your environment is secured from this vulnerability.</p>
<h4 data-text="What should I do?" id="what-should-i-do_12" tabindex="-1">What should I do?</h4>
<p>
       We recommend upgrading to VMware HCX version 4.9.2.</p>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25019">VMSA-2024-0021</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38214">CVE-2024-38814</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-051</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-051</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-051"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-09-18</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       VMware disclosed multiple vulnerabilities in <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968">VMSA-2024-0019</a> that impact vCenter components deployed in customer environments.
       </p>
<h4 data-text="VMware Engine impact" id="impact" tabindex="-1">VMware Engine impact</h4>
<ul>
<li>Google has already disabled any potential exploit of this
       vulnerability. For example, Google has blocked the ports through which
       this vulnerability could be exploited.
       </li>
<li>In addition, Google ensures all future deployments of vCenter are not
       exposed to this vulnerability.
       </li>
</ul>
<h4 data-text="What should I do?" id="what-should-i-do_13" tabindex="-1">What should I do?</h4>
<p>
       No further action is required at this time.
       </p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812">CVE-2024-38812</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813">CVE-2024-38813</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-040</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-040</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-040"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-07-01</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       A vulnerability CVE-2024-6387 was discovered in OpenSSH server (sshd).
       This vulnerability is exploitable remotely on glibc-based linux systems:
       an unauthenticated remote code execution as root, because it affects
       sshd's privileged code, which is not sandboxed and runs with full privileges.
       <br/><br/>
       At the time of publication, exploitation is believed to be difficult–requiring
       winning a race condition, which is hard to successfully exploit and may
       take several hours per machine being attacked.
       We are not aware of any exploitation attempts.
       </p>
<h4 data-text="What should I do?" id="what-should-i-do_14" tabindex="-1">What should I do?</h4>
<ol>
<li>Apply updates from Linux distributions to your workloads as they
          become available. Please refer to guidance from Linux distributions.
          </li>
<li>If updating is not possible, consider turning OpenSSH off until
          it can be patched.
          </li>
<li>If OpenSSH needs to be left on, you can also execute a configuration
          update which eliminates the race case condition for the exploit.
          This is a runtime mitigation. To apply the changes in the sshd config,
          this script will restart the sshd service.
          <div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">
#!/bin/bash
set -e

SSHD_CONFIG_FILE=/etc/ssh/sshd_config
# -c: count the matches
# -q: don't print to console
# -i: sshd_config keywords are case insensitive.
if [[ "$(grep -ci '^LoginGraceTime' $SSHD_CONFIG_FILE)" -eq 0 ]]; then
    echo "LoginGraceTime 0" &gt;&gt; "$SSHD_CONFIG_FILE"
    echo "Set the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
else
    sed -i 's/^LoginGraceTime.*$/LoginGraceTime 0/' /etc/ssh/sshd_config
    echo "Changed the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
fi
# Restart the sshd service to apply the new config.
systemctl restart sshd
          </pre></devsite-code>
</li>
<li>Finally, monitor for any unusual network activity involving SSH servers.
          </li>
</ol>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387">CVE-2024-6387</a></li>
<li><a href="https://knowledge.broadcom.com/external/article?articleNumber=371126">Broadcom VMware Cloud Foundation Response</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-037</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-037</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-037"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-06-18</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       VMware disclosed multiple vulnerabilities in <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453">VMSA-2024-0012</a>
       that impact vCenter components deployed in customer environments.
       </p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact" tabindex="-1">VMware Engine impact</h4>
<ul>
<li>The vulnerability can be exploited by accessing specific ports in vCenter
       Server. Google has already blocked the vulnerable ports on vCenter
       server, which prevents any potential exploits of this vulnerability.
       </li>
<li>In addition, Google ensures all future deployments of vCenter are not
       exposed to this vulnerability.
       </li>
</ul>
<h4 data-text="What should I do?" id="what-should-i-do_15" tabindex="-1">What should I do?</h4>
<p>
       No further action is required at this time.
       </p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37079">CVE-2024-37079</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37080">CVE-2024-37080</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37081">CVE-2024-37081</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-016</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2024-016</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2024-016"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-03-05</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
       VMware disclosed multiple vulnerabilities in <a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html">VMSA-2024-0006</a> that
       impact ESXi components deployed in customer environments.
       </p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_1" tabindex="-1">VMware Engine impact</h4>
<p>
       Your private clouds have been updated to address the security vulnerability.
       </p>
<h4 data-text="What should I do?" id="what-should-i-do_16" tabindex="-1">What should I do?</h4>
<p>
       No action is needed on your part.
       </p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html">VMSA-2024-0006</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22252">CVE-2024-22252</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22253">CVE-2024-22253</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22254">CVE-2024-22254</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22255">CVE-2024-22255</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2023-034</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2023-034</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2023-034"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2023-10-25</p><p><strong>Updated: </strong>2023-10-27</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>VMware disclosed multiple vulnerabilities in
        <a class="external" href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html">VMSA-2023-0023</a>
        that impact vCenter components deployed in customer environments.</p>
<h4 data-text="VMware Engine impact" id="20231026_impact" tabindex="-1">VMware Engine impact</h4>
<ul>
<li>The vulnerability can be exploited by accessing specific ports
        in vCenter Server. These ports are not exposed to the public
        internet.</li>
<li>If your vCenter ports 2012/tcp, 2014/tcp, and 2020/tcp
        are not accessible by untrusted systems, then you are not exposed to this
        vulnerability.</li>
<li>Google has already blocked the vulnerable ports on vCenter server,
        preventing any potential exploit of this vulnerability.</li>
<li>In addition, Google will ensure all future deployments of vCenter
         server are not exposed to this vulnerability.</li>
<li>At the time of the bulletin, VMware is not aware of any exploitation "in the wild".
         For more details please refer to the <a class="external" href="https://core.vmware.com/resource/vmsa-2023-0023-questions-answers#are-the-vulnerabilities-disclosed-being-exploited-in-the-wild">VMware documentation</a> for more information.</li> </ul>
<h4 data-text="What should I do?" id="what-should-i-do_17" tabindex="-1">What should I do?</h4>
<p>No further action is required at this time.</p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a class="external" href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html">CVE-2023-34048, CVE-2023-34056</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2023-027</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2023-026</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2023-026"/>
    <content type="html"><![CDATA[<b>Published:</b><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)</p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_2" tabindex="-1">VMware Engine impact</h4>
<p>VMware vCenter Server (vCenter Server) and VMware Cloud Foundation (Cloud Foundation).</p>
<h4 data-text="What should I do?" id="what-should-i-do_18" tabindex="-1">What should I do?</h4>
<p>Customers are not impacted and no action needs to be taken.</p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a class="external" href="https://www.vmware.com/security/advisories/VMSA-2023-0014.html">CVE-2023-20893</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2023-025</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2023-025</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2023-025"/>
    <content type="html"><![CDATA[<b>Published:</b><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Intel recently announced <a class="external" href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00828.html">Intel Security Advisory INTEL-SA-00828</a> impacting some of their processor families. You are encouraged to assess your risks based on the advisory.</p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_3" tabindex="-1">VMware Engine impact</h4>
<p>Our fleet utilizes the impacted processor families. In our deployment,
        the entire server is dedicated to one customer. Hence, our deployment
        model doesn't add any additional risk to your assessment of this vulnerability.</p>
<p>We are working with our partners to obtain necessary patches and will
        be deploying these patches on priority across the fleet using the
        standard upgrade process in the next several weeks.</p>
<h4 data-text="What should I do?" id="what-should-i-do_19" tabindex="-1">What should I do?</h4>
<p>No action is needed on your part, we are working on upgrading all the
         impacted systems.</p>
</td>
<td>High</td>
<td>
<ul>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40982">CVE-2022-40982</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2021-023</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2021-023</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2021-023"/>
    <content type="html"><![CDATA[<b>Published:</b><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per VMware security advisory VMSA-2021-0020, VMware received reports
          of multiple vulnerabilities in vCenter. VMware has made updates
          available to remediate these vulnerabilities in affected VMware
          products.</p>
<p>We have already applied the patches provided by VMware for the
          vSphere stack to Google Cloud VMware Engine per the VMware security advisory.
          This update addresses the security vulnerabilities described in
          CVE-2021-22005, CVE-2021-22006, CVE-2021-22007, CVE-2021-22008, and
          CVE-2021-22010. Other non-critical security issues will be addressed
          in the upcoming VMware stack upgrade (per the advance notice sent in
          July, more details will be provided soon on the specific timeline of
          the upgrade).</p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_4" tabindex="-1">VMware Engine impact</h4>
<p>Based on our investigations, no customers were found to be
          impacted.</p>
<h4 data-text="What should I do?" id="what-should-i-do_20" tabindex="-1">What should I do?</h4>
<p>Because VMware Engine clusters are not affected by this
          vulnerability, no further action is required.</p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a class="external" href="https://www.vmware.com/security/advisories/VMSA-2021-0020.html">VMSA-2021-0020</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22005">CVE-2021-22005</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22006">CVE-2021-22006</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22007">CVE-2021-22007</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22008">CVE-2021-22008</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22010">CVE-2021-22010</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2021-010</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2021-010</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2021-010"/>
    <content type="html"><![CDATA[<b>Published:</b><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per VMware security advisory VMSA-2021-0010, remote code execution and
          authentication bypass vulnerabilities in vSphere Client (HTML5) were
          privately reported to VMware. VMware has made updates available to
          remediate these vulnerabilities in affected VMware products.</p>
<p>We have applied the patches provided by VMware for the vSphere stack
          per the VMware security advisory. This update addresses security
          vulnerabilities described in CVE-2021-21985 and CVE-2021-21986. The
          image versions running in your VMware Engine private
          cloud don't reflect any change at this time to indicate the patches
          applied.
          Please rest assured that appropriate patches have been installed and
          your environment is secured from these vulnerabilities.</p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_5" tabindex="-1">VMware Engine impact</h4>
<p>Based on our investigations, no customers were found to be impacted.</p>
<h4 data-text="What should I do?" id="what-should-i-do_21" tabindex="-1">What should I do?</h4>
<p>Because VMware Engine clusters are not affected by this
          vulnerability, no further action is required.</p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a class="external" href="https://www.vmware.com/security/advisories/VMSA-2021-0010.html">VMSA-2021-0010</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21985">CVE-2021-21985</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21986">CVE-2021-21986</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2021-002</title>
    <id>tag:google.com,2016:google-cloud-vmware-engine-security-bulletins#gcp-2021-002</id>
    <updated>2026-07-29T17:07:38.222315+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/vmware-engine/docs/security-bulletins#gcp-2021-002"/>
    <content type="html"><![CDATA[<b>Published:</b><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Per VMware security advisory VMSA-2021-0002, VMware received reports of
          multiple vulnerabilities in VMware ESXi and vSphere Client (HTML5).
          VMware has made updates available to remediate these vulnerabilities in
          affected VMware products.</p>
<p>We have applied the officially documented workarounds for the vSphere
          stack per the VMware security advisory. This update addresses security
          vulnerabilities described in CVE-2021-21972, CVE-2021-21973, and
          CVE-2021-21974.</p>
<h4 data-text="VMware Engine impact" id="vmware-engine-impact_6" tabindex="-1">VMware Engine impact</h4>
<p>Based on our investigations, no customers were found to be impacted.</p>
<h4 data-text="What should I do?" id="what-should-i-do_22" tabindex="-1">What should I do?</h4>
<p>We recommend upgrading to the latest version of HCX.</p>
</td>
<td>Critical</td>
<td>
<ul>
<li><a class="external" href="https://www.vmware.com/security/advisories/VMSA-2021-0002.html">VMSA-2021-0002</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972">CVE-2021-21972</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21973">CVE-2021-21973</a></li>
<li><a class="external" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21974">CVE-2021-21974</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
