Views
6

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

Google Cloud release notes cover Apigee X 1-17-0-apigee-8, Apigee hybrid v1.16.4, GKE (2026-R20), and Container-Optimized OS security updates. Highlights include multiple Linux kernel CVE fixes, new GKE versions, and several feature additions across Cloud services. Reference IDs: 1.35.100-gke.72, v3.14.

Update Details

Security

  • Container-Optimized OS fixed many Linux kernel vulnerabilities, including CVE-2025-38584, CVE-2026-23473, CVE-2026-43060, CVE-2026-43063, CVE-2026-43065, CVE-2026-43066, CVE-2026-43067, CVE-2026-43068, CVE-2026-43071, CVE-2026-43073, CVE-2026-43079, CVE-2026-43085, CVE-2026-43086, CVE-2026-43089, CVE-2026-43090, CVE-2026-43091, CVE-2026-43093, CVE-2026-43094, CVE-2026-43099, CVE-2026-43107, CVE-2026-43112, CVE-2026-43114, CVE-2026-43117, CVE-2026-43329, CVE-2026-43332, CVE-2026-43333, CVE-2026-43336, CVE-2026-43338, CVE-2026-43339, CVE-2026-43341, CVE-2026-43350, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361, CVE-2026-43362, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43374, CVE-2026-43383, CVE-2026-43392, CVE-2026-43393, CVE-2026-43394, CVE-2026-43403, CVE-2026-43409, CVE-2026-43438, CVE-2026-43439, CVE-2026-43441, CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43466, CVE-2026-43469, CVE-2026-43470, CVE-2026-43472, CVE-2026-43475, CVE-2026-43482, CVE-2026-43486, CVE-2026-43487, CVE-2026-46333.
  • Container-Optimized OS fixed argument injection in toolbox.
  • Container-Optimized OS fixed EFI variable out-of-bounds read in grub config parsing.
  • Container-Optimized OS updated OpenSSH to address CVE-2026-35385, CVE-2026-35386, and CVE-2026-35414.
  • Container-Optimized OS updated OpenSSL to address CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31790.
  • Container-Optimized OS updated Go to v1.25.9 to address CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-27140, and CVE-2026-27144.
  • Container-Optimized OS updated containerd to v2.2.3 to address CVE-2026-35469.
  • Container-Optimized OS updated libgcrypt to v1.10.4 to address CVE-2026-41989.
  • Container-Optimized OS updated protobuf to address CVE-2026-0994.
  • Container-Optimized OS updated xz-utils to address CVE-2026-34743.
  • Apigee X fixed Model Armor response parsing to handle unknown fields and prevent policy failures from future field additions.
  • Security Command Center deprecated the Enterprise service tier and will shut it down on 2027-05-21.

Bug Fixes

  • Apigee hybrid v1.16.4 fixed missing container images in the gcr.io/apigee-release/hybrid/ repository.
  • Google Distributed Cloud for VMware 1.35.100-gke.72 fixed an issue preventing administrators from running cluster health checks and gathering diagnostics on non-advanced user clusters managed by an advanced admin cluster.
  • Container-Optimized OS fixed and upgraded multiple packages, including dash, rsync, sqlite, expat, libcap, lsof, sosreport, google-breakpad, and docker-credential-helpers.
  • Container-Optimized OS updated runtime sysctl defaults and removed several deprecated nf_conntrack_dccp and XFS settings.

New Features

  • AlloyDB for PostgreSQL users can now list and use the AlloyDB toolset provided by the AlloyDB remote MCP server.
  • App Engine standard environment Migration hub is available for Go, Java, Node.js, PHP, Python, and Ruby to help migrate services to Cloud Run and provide cost-saving recommendations.
  • Cloud Asset Inventory added public availability for new resource types across Apigee, Cloud KMS, and Hypercompute Cluster APIs.
  • Cloud Load Balancing GA: Zonal affinity is now generally available for internal passthrough Network Load Balancers.
  • Config Controller now includes Config Connector v1.148.0-cc.3 and Config Sync v1.23.3.
  • Container-Optimized OS added the cos_kernel_args tool for manipulating kernel command-line arguments in a COS image.
  • Container-Optimized OS added nvidia-fs support to the COS GPU installer.
  • Google Cloud's Agent for SAP v3.14 is GA with CMEK support for disk encryption during disk snapshot-based SAP HANA recovery.
  • Secure Web Proxy Preview now supports listening on all ports from 1 to 65535 when deployed as next hop.
  • Security Command Center Preview added Artifact guard and new Cloud Build toxic-combination detection in Risk Engine.

Known Issues

  • Apigee X rollout began on May 21, 2026 and may take four or more business days to complete across all Google Cloud zones.
  • Google Distributed Cloud versions may take approximately 7 to 14 days to become available in Google Cloud console, gcloud, and Terraform after release.
  • GKE version availability may vary during rollout and can take multiple days to reach all zones.

Hints

  • Apigee hybrid patch releases integrate container images with the Helm charts; upgrading via the Helm chart typically updates images automatically.
  • For Apigee hybrid v1.16.4, review the upgrade guidance before applying the patch.
  • For Google Distributed Cloud releases, verify third-party storage vendor qualification before upgrading or installing.
  • For GKE, new versions are available by channel and may not appear immediately due to staged rollout.
  • Container-Optimized OS release notes include multiple image tracks, including cos-129-19506-120-97, cos-dev-133-19804-0-0, cos-121-18867-381-132, cos-125-19216-395-31, and cos-117-18613-613-15.

Links

Product Information

Vendor: Google

Product: Cloud

Product type: Other

Platform: Web

Version: 1-17-0-apigee-8; v1.16.4; 1.35.100-gke.72; (2026-R20); cos-129-1

Vendor release date: May 21, 2026

Published on updatealert.io: Jun 4, 2026

Description: Cloud platform for compute, data, networking, and developer services.