CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-18236: Google ADK Continuation Forgery

August 6, 2026

Google ADK for Python before 2.5.0 allows attackers to forge confirmation events in session history, causing unauthorized execution of sensitive tools. CVSS v4.0 score 9.3. Fixed in ADK 2.5.0.