CVE-2026-19407: Google Cloud Gemini Enterprise Agent Platform SDK For Python

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Affected products

  • Google Cloud Gemini Enterprise Agent Platform SDK For Python: from 1.16.0, before 1.165.1 (fixed in 1.165.1)

Published 2026-09-15. Last modified 2026-09-21.