CVE-2026-67180: Google Turbinia

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

Affected products

  • Google Turbinia: before 2026-07-10 (fixed in 2026-07-10)

Published 2026-08-11. Last modified 2026-08-26.