CVE-2026-1727Disclosure

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in "bucket squatting" by establishing these buckets before a victim's initial use. All versions after December 12th, 2025 have been updated to protect from this vulnerability. No user action is required for this.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-07: 1Mentions · 2026-04-20: 1Mentions · 2026-06-16: 1Mentions · 2026-07-10: 1Active Exploitation · 2026-07-10: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-16: 1Technical Details · 2026-07-10: 102-0602-0704-2006-1607-10
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-071
Patch1
2026-04-201
Disclosure1
2026-06-161
Patch1
2026-07-101
Active Exploitation1
Full discourse6 posts
  • OmerAF@omer_asfu
    Disclosure

    I found this squatting pattern recurring across three major GCP services: • VertexSquat (CVE-2026-2473): Full RCE in Vertex AI. • GeminiSquat (CVE-2026-1727): Gemini Enterprise. • MountSquat: Takeover of Cloud Run mount volumes.

    Post summary

    The user has identified new RCE vulnerabilities in multiple Google Cloud services, naming the CVEs and describing the affected components. No PoC, exploit, or patch information is provided.

    120421.0K
    655 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting predictable bucket naming patterns to silently redirect organizational data streams to attacker-controlled storage. CVE-2026-2473 and CVE-2026-1727 demonstrate how misconfigured cloud storage enables privilege escalation and lateral movement across cloud resources. Runtime segmentation could help contain post-compromise activity. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/threatsday-cloud-bucket-hijacking-2026

    Post summary

    The analysis confirms attackers actively exploiting predictable bucket naming patterns to achieve privilege escalation and lateral movement in cloud resources, but does not provide PoC or exploitation tools, nor any mitigation information.

    1000068
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1727 The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names w… https://www.cve.org/CVERecord?id=CVE-2026-1727

    Post summary

    CVE-2026-1727 exposes sensitive data in the Agentspace service due to predictable Google Cloud Storage bucket names.

    00010205
    56.5K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Patch

    🚨 UPDATE — Vertex AI bucket squatting: This isn't a one-off. Focal Security separately disclosed THREE Google Cloud bucket squatting flaws this year — GeminiSquat (CVE-2026-1727) in Gemini Enterprise, MountSquat in Cloud Run, and VertexSquat (CVE-2026-2473) in Vertex AI Experiments. All three: no credentials needed, cross-tenant code execution. No CVE has been assigned to the new 'Pickle in the Middle' flaw yet. But the pattern is clear: Google Cloud's predictable bucket naming convention is a systemic architectural problem, not a one-time bug. Check your google-cloud-aiplatform version in notebooks, CI jobs, and training pipelines — not just production. Update to v1.148.0 now. 👇 https://thehackernews.com/2026/06/google-vertex-ai-sdk-flaw-let-attackers.html

    Post summary

    Focal Security disclosed three Google Cloud bucket squatting CVEs that grant cross‑tenant code execution without credentials, and the article urges users to upgrade to v1.148.0 to mitigate the risk.

    0000063
    84 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Google Cloud Gemini Enterprise flaw (CVE-2026-1727) exposes sensitive data via predictable bucket names. All versions before Dec 12, 2025 are affected. Patch applied — verify your version! 🔒 https://radar.offseq.com/threat/cve-2026-1727-cwe-200-exposure-of-sensitiv... https://t.co/9QiIq6GI6m

    Post summary

    Google Cloud Gemini Enterprise CVE-2026-1727 exposes sensitive data through predictable bucket names; patch has been applied and all versions before Dec 12 2025 are affected.

    0000076
    268 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1727: Information Disclosure via Bucket... Predictable bucket names in Agentspace enable trivial cloud squatting attacks - grab GCS buckets before victims provisio... https://zerodaysignal.com/vulnerability/CVE-2026-1727 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑1727 is an information disclosure vulnerability in Agentspace caused by predictable bucket names, enabling attackers to grab GCS buckets before victims provision them.

    0000079
    132 followersView on X

Explore more