Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
On May 20, 2026, Google published security bulletin GCP-2026-034 for Apigee. It addresses CVE-2026-2264, an SSRF issue in `SetIntegrationRequest` that could expose service account tokens.
IntegrationRegion in SetIntegrationRequest lacks validation, enabling Server-Side Request Forgery (SSRF) and service account token exfiltration when an attacker controls the flow variable.AI.AGG is available in Preview for semantic aggregation of unstructured input data.mediaResolution declarations, including MEDIA_RESOLUTION_ULTRA_HIGH, for images, videos, and PDFs.bigquery-adminbot@system.gserviceaccount.com.us-central1 and europe-west4, with serving restricted to the US and EU multi-region endpoints.europe-west2; existing CUDs remain valid and ve1 nodes can still be used with on-demand pricing.Vendor: Google
Product: Cloud
Product type: Other
Platform: Web
Version: 20260511.00
Vendor release date: May 20, 2026
Published on updatealert.io: Jun 4, 2026
Description: Cloud platform for compute, data, networking, and developer services.