Google Cloud Patches Three Application Integration Vulnerabilities
Quick Answer
Google Cloud published three Application Integration bulletins covering one High and two Critical vulnerabilities. The authority says the managed service was patched in June and no customer action is required; owners should verify their integration inventory, confirm no unsupported equivalent is in use, and retain the bulletin review as evidence.
Confirm Scope And Apply The Supported Fix
What to do now: Identify Application Integration workloads using Email Task, JavaScript Task, or task configuration features, record the service and project owners, confirm the workload is on the Google-managed service covered by the bulletins, validate representative integrations, and retain the no-action-required assessment.
Last verified: 2026-09-28 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Google Cloud Application Integration before the authority's June 17, June 28, and June 30 managed-service patches |
|---|---|
| Advisory | GCP-2026-064 / GCP-2026-065 / GCP-2026-066 |
| CVEs | CVE-2026-19759, CVE-2026-81375, CVE-2026-81867 |
| Authoritative release date | 2026-09-28 (date stated in GCP-2026-064, GCP-2026-065, and GCP-2026-066) |
| Authority revision date | No separate material revision date stated by Google Cloud |
| Affected versions | Application Integration task implementations before the bulletin-specific managed-service patch dates; Google states that no customer action is required. |
| Fixed version | Google-managed patches applied June 17, June 28, and June 30, 2026; no customer software update is required |
| CVSS base score | Not provided by the authority |
| CVSS severity | High to Critical |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Google Cloud corrected an authorization flaw in task configuration, unsafe deserialization in the JavaScript Task, and a confused-deputy flaw in the Email Task. The authority says the managed service was patched and no customer action is required.
What To Validate Now
- Inventory. Locate Google Cloud projects and Application Integration workflows using Email Task, JavaScript Task, or task configuration features; record owners and critical dependencies.
- Establish applicability. Confirm each workload uses the Google-managed Application Integration service covered by the three bulletins. Do not extend the no-action statement to self-managed or different products.
- Remediate. Do not apply an unsupported customer-side patch. Google states that the service fixes were applied and no customer action is required; follow any later authority revision.
- Validate. Exercise representative integrations, review recent failures or unexpected task behavior, confirm owners accept the managed-service status, and retain the assessment and bulletin versions.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
The official severity is not evidence that a tenant was exploited. Avoid disruptive changes to managed components, and recheck the authoritative bulletins if Google changes affected scope or required action.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

