Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-054

A security vulnerability has been found in the Trusted Computing Group's TPM 2.0 reference implementation code used by Google Cloud. It affects all known published versions of this code. Google Cloud is handling the fix by updating the affected systems internally, so customers do not need to take any action.

Published 2/9/2026, 6:28:49 pmVerified 4/9/2026, 1:21:33 amRevision 1
Google Cloud unrated network security advisory visual

In plain language

What this advisory means

A security vulnerability has been found in the Trusted Computing Group's TPM 2.0 reference implementation code used by Google Cloud. It affects all known published versions of this code. Google Cloud is handling the fix by updating the affected systems internally, so customers do not need to take any action.

Technical explanation

How the issue affects the environment

The vulnerability identified as CVE-2026-6726 (also known as TCGVRT0010) exists in the Trusted Computing Group's TPM 2.0 reference implementation across all released versions (v1.16, v1.38, v1.59, v1.83, v184). This issue pertains to the TPM (Trusted Platform Module) 2.0 software stack, which is critical for hardware-based security functions such as secure key storage and device attestation. The vulnerability could potentially undermine these security guarantees. Google Cloud is proactively deploying updates to patch this vulnerability across their infrastructure during planned maintenance, requiring no direct action from customers.

Operational impact

Why teams should care

Since TPM 2.0 is used to ensure platform integrity and secure cryptographic operations, this vulnerability could affect the trustworthiness of systems relying on these functions within Google Cloud. However, because Google is applying the updates proactively, customers' workloads are protected without requiring their involvement. There is no reported exploit or active customer impact at this time, minimizing business risk for Google Cloud customers.

Immediate action

Google Cloud will proactively update affected systems during their standard and planned maintenance windows to apply necessary fixes. Customers are not required to take any immediate action.

Affected and fixed releases

Affected versionsv1.16, v1.38, v1.59, v1.83, v184
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

The advisory does not specify any customer-side workarounds. Mitigation is managed entirely by Google Cloud.

Evidence and validation checklist

  • Vulnerability CVE-2026-6726 identified in TPM 2.0 reference implementation code.
  • All published versions of TPM 2.0 code (v1.16 to v184) affected.
  • Google Cloud will update systems proactively during maintenance windows.
  • No customer action required as per the Google Cloud Security Bulletin.

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source