CVE-2026-19407EPSS p42.2%

CVE-2026-19407CVE-2026-19407

Description

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Scoring

EPSS0.52% probability of exploitation · percentile 42.2% · 2026-10-05T12:00:23Z
Last modified2026-09-21
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.