GCP Weekly[verified]@gcpweeklyPatch
The message reports an update to google-guest-agent aimed at remediating CVE-2026-33186 on Debian and Rocky Linux images.
GCP Weekly[verified]@gcpweeklyPatch
Google has upgraded google‑guest‑agent on Debian and Rocky Linux images to apply a fix for CVE‑2026‑33186. The post confirms a vendor patch but lacks exploit details.
ThreatCluster[verified]@threatclusterPatch
SUSE has issued security fixes for CVE-2026-33186 and CVE-2026-33814, addressing an authorization bypass and an HTTP/2 DoS in Public Cloud Module 12. No PoC, exploit code, or evidence of active exploitation is mentioned.
ThreatCluster[verified]@threatclusterDisclosure
A new vulnerability, CVE-2026-33186, affecting openSUSE Leap 16.0 components via an HTTP/2 header bypass in grpc was reported, but no PoC, exploit, or patch is provided.
ThreatCluster[verified]@threatclusterPatch
Patch released for openSUSE Leap 15.6 and Ubuntu Server 22.04 to address critical Terraform provider flaws CVE-2026-25934 and CVE-2026-33186, which involve an HTTP/2 ':path' bug rated CVSS 9.1, and PoC code was released on 2026-04-07.
ThreatCluster[verified]@threatclusterPoC
A critical authorization bypass (CVE‑2026‑33186) affecting google‑cloud‑sap‑agent 3.12 has been disclosed, with a PoC released and CVSS score up to 9.1, but no patch or evidence of active exploitation yet.
WindowsForum[verified]@windowsforumDisclosure
The post announces a new Windows‑specific CVE (CVE‑2026‑33186) involving a missing leading slash in gRPC‑Go that enables an authorization bypass; it includes a forum link but offers no PoC, exploit code, or patch details.
motch | セキュリティ🛡️[verified]@motch_devDisclosure
The tweet announces a critical authorization-bypass flaw (CVE-2026-33186) in gRPC-Go caused by missing leading slashes in paths; it urges upgrading to version 1.79.3 or later to mitigate.