<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Google Kubernetes Engine (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/google-kubernetes-engine.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/google-kubernetes-engine-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Google Kubernetes Engine (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-4810 – A Code Injection and Missing Authentication vulnerability in Google Agent Develo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4810</guid>
    <pubDate>Mon, 13 Apr 2026 09:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4810</strong></p>
  <p>A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance.  This vulnerability was patched in versions 1.28.1 and 2.0.0a2.   Customers need to redeploy the upgr…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2121 – Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2121</guid>
    <pubDate>Wed, 12 Feb 2020 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2121</strong></p>
  <p>Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2121">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
