<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:gcp-release-notes</id>
  <title>Google Cloud Platform (GCP) - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/gcp-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-06-23T00:00:00-07:00</updated>

  <entry>
    <title>June 23, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_23_2026</id>
    <updated>2026-06-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_23_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AI Hypercomputer</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can use Gemini in the Google Cloud console as
an AI-powered interface to evaluate hardware options, estimate deployment costs,
and view recommended configurations for your clusters. Prompting
Gemini helps you reach an optimal configuration for your cluster
before you create or modify the cluster. For more information, see
<a href="https://docs.cloud.google.com/ai-hypercomputer/docs/design-with-gemini">Design and optimize your cluster with Gemini</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics">Conversational analytics</a> in BigQuery
is now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA) and includes the following features:</p>
<ul>
<li>You can select whether an agent can only use generally available models, or
a mix of preview and generally available models.</li>
<li>You can change the thinking mode of an agent within a conversation.</li>
<li>Agents can ask clarifying questions about your input prompt.</li>
<li>Agent responses include context citations, to help you understand the specific 
sources used to generate the answer.</li>
<li>Parameters are supported in verified queries.</li>
<li><p>Agents can use the following AI functions to answer your questions:</p>
<ul>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"><code>AI.KEY_DRIVERS</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-if"><code>AI.IF</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-score"><code>AI.SCORE</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-classify"><code>AI.CLASSIFY</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-similarity"><code>AI.SIMILARITY</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-search"><code>AI.SEARCH</code></a></li>
</ul></li>
</ul>
<p>You can also create a
<a href="https://docs.cloud.google.com/bigquery/docs/create-conversations#datasets">conversation with a dataset</a>.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can use Gemini in the Google Cloud console as
an AI-powered interface to evaluate hardware options, estimate deployment costs,
and view recommended configurations for your Compute Engine instances.
Prompting Gemini helps you reach an optimal configuration for
your workload before you create or modify a compute instance. For more
information, see
<a href="https://docs.cloud.google.com/compute/docs/design-with-gemini">Design your compute infrastructure with Gemini</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management</strong></p>
<p>Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface. Use the new <strong>Ask Gemini Cloud Assist</strong> button to get help with feed creation, setup, and general troubleshooting questions.</p>
<p>Click <strong>Ask Gemini Cloud Assist</strong> to open the Gemini Cloud Assist panel and ask questions to get guidance on:</p>
<ul>
<li>Configuring and managing data feeds.</li>
<li>Understanding ingestion pre-requisites and setup steps for different log sources.</li>
<li>Resolving common setup issues.</li>
</ul>
<p><em>Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.</em></p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/feed-management-overview">Feed management overview</a>.</p>
<h3>Change</h3>
<p><strong>Ingestion metrics reporting correction</strong></p>
<p>Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.</p>
<p>Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.</p>
<p>Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.</p>
<p>If you have questions or need assistance, contact Google Security Operations support.</p>
<h3>Breaking</h3>
<p><strong>Critical Notice: Upcoming reservation of siemAlertId field</strong></p>
<p>Effective July 5, 2026, the <code>siemAlertId</code> field will be strictly reserved for
internal Chronicle SIEM alert IDs.</p>
<p>Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named
<code>siemAlertId</code> in any of your data ingestion configurations, please migrate to a
different field name immediately to prevent data loss.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Ask Gemini Cloud Assist in Feed Management</strong></p>
<p>Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general troubleshooting questions.</p>
<p>A new <strong>Ask Gemini Cloud Assist</strong> button is now available in the Feed Management interface. You can click this button to open the Gemini Cloud Assist panel and ask questions to get guidance on:</p>
<ul>
<li>Configuring and managing data feeds.</li>
<li>Understanding ingestion pre-requisites and setup steps for different log sources.</li>
<li>Resolving common setup issues.</li>
</ul>
<p><em>Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.</em></p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/feed-management-overview">Feed management overview</a>.</p>
<h3>Change</h3>
<p><strong>Ingestion metrics reporting correction</strong></p>
<p>Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.</p>
<p>Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.</p>
<p>Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.</p>
<p>If you have questions or need assistance, contact Google Security Operations support.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Breaking</h3>
<p><strong>Critical Notice: Upcoming reservation of siemAlertId field</strong></p>
<p>Effective July 5, 2026, the <code>siemAlertId</code> field will be strictly reserved for
internal Chronicle SIEM alert IDs. </p>
<p>Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named 
<code>siemAlertId</code> in any of your alert ingestion configurations, please
migrate to a different field name immediately to prevent data loss.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>You can control data lineage ingestion for BigQuery and Managed Service for Apache Airflow at the organization, folder, or project level. This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/about-data-lineage#control-lineage-ingestion">Control data ingestion</a>.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>ABAP SDK for Google Cloud version 1.14 (On-premises or any cloud edition)</strong></p>
<p>Version 1.14 of the on-premises or any cloud edition of the ABAP SDK for Google
Cloud is generally available (GA).</p>
<p>This version resolves an issue that occurred during signature verification for Cloud Storage content repository and removes an unreferenced node from the SPRO configuration menu.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sap/docs/abap-sdk/on-premises-or-any-cloud/whats-new#version-1-14">What's new with the ABAP SDK for Google Cloud</a>.</p>
<h3>Announcement</h3>
<p><strong>BigQuery Connector for SAP version 2.15</strong></p>
<p>Version 2.15 of the BigQuery Connector for SAP is generally available (GA).
This version resolves issues related to column descriptions in standalone SLT
system configurations and attribute consistency in Pub/Sub messages during
Change Data Capture (CDC) replication.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sap/docs/bq-connector/whats-new#version-2-15">What's new with BigQuery Connector for SAP</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/sensitive-data-protection/docs/infotypes-reference#image-context">Image safety classification infoTypes</a> are now supported in <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InspectConfig#excludebyimagefindings">ExcludeByImageFindings</a></code> and <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InspectConfig#adjustbyimagefindings">AdjustByImageFindings</a></code> detection rules.</p>
<p>For information about configuring these rules, see <a href="https://docs.cloud.google.com/sensitive-data-protection/docs/creating-custom-infotypes-rules">Modifying infoType detectors
to refine scan results</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner supports
<a href="https://docs.cloud.google.com/spanner/docs/latency-points#direct_connectivity">direct connectivity</a>.
When enabled, your application traffic is routed directly to
Spanner servers, bypassing the Google Front End (GFE) servers.
This can reduce your overall latency.
Direct connectivity is
<a href="https://docs.cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 22, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_22_2026</id>
    <updated>2026-06-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_22_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AI Hypercomputer</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: RoCE VPC networks for VM instances support assigning alias IP
ranges to <code>MRDMA</code> vNICs. For more information about these features, see the
following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc/docs/rdma-network-profiles">RDMA network profiles</a></li>
<li><a href="https://docs.cloud.google.com/vpc/docs/alias-ip">Alias IP ranges</a></li>
</ul>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 22nd, 2026, we released an updated version of Apigee (1-17-0-apigee-10).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>519996459</strong></td>
<td><strong>Security fix for Apigee.</strong> Upgraded the Apigee ingress gateway to patch the following vulnerabilities: <p><ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14993">CVE-2019-14993</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39155">CVE-2021-39155</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39156">CVE-2021-39156</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23635">CVE-2022-23635</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29181">CVE-2026-29181</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33811">CVE-2026-33811</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33814">CVE-2026-33814</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34986">CVE-2026-34986</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39820">CVE-2026-39820</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39836">CVE-2026-39836</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046">CVE-2026-4046</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499">CVE-2026-42499</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501">CVE-2026-42501</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42504">CVE-2026-42504</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31045">CVE-2022-31045</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27145">CVE-2026-27145</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32282">CVE-2026-32282</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32288">CVE-2026-32288</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32289">CVE-2026-32289</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39350">CVE-2026-39350</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39817">CVE-2026-39817</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39819">CVE-2026-39819</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39823">CVE-2026-39823</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39825">CVE-2026-39825</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39826">CVE-2026-39826</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41413">CVE-2026-41413</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42507">CVE-2026-42507</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437">CVE-2026-4437</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4438">CVE-2026-4438</a></li></ul></p></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong></td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>515788622</strong></td>
<td>Upgraded the default outbound TLS protocol from TLSv1.2 to TLSv1.3 on JVMs that support it. Per-proxy <code>&lt;SSLInfo&gt;&lt;Protocols&gt;</code> settings continue to take precedence, and the new <code>HTTPClient.outbound.tls.protocol</code> override lets operators force a specific protocol.</td>
</tr>
<tr>
<td><strong>184266748</strong></td>
<td>Fixed an issue where ApigeeDatastore TLS certificate creation could fail in namespaces with longer names when the certificate common name exceeded the 64-byte limit.</td>
</tr>
<tr>
<td><strong>286069772</strong></td>
<td>Added a per-gateway <code>proxyProtocol.mode</code> property (strict, permissive, disable) on Apigee ingress gateway components to opt in to HAProxy PROXY-protocol parsing. The property defaults to disable.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td>Updates to infrastructure and libraries.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can use the BigQuery Data Transfer Service to transfer metadata from the
following data sources into Knowledge Catalog:</p>
<ul>
<li><a href="https://docs.cloud.google.com/bigquery/docs/oracle-transfer#transfer_metadata">Oracle</a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/mysql-transfer#transfer_metadata">MySQL</a></li>
</ul>
<p>This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Resource-based CUD recommendations available for Compute Engine GPUs, Local SSD disks, and OS licenses</strong></p>
<p>Resource-based committed use discount (CUD) recommendations are generally available (GA) for GPUs, Local SSD disks, and premium operating system (OS) licenses.</p>
<p>CUD recommendations provide insight into any additional commitments that you can
purchase to optimize the costs of the resources that you run. You can use these
recommendations and purchase commitments for resource usage that isn't covered
by commitments and is being charged at list prices. Google Cloud analyzes your
compute instance spending trends with and without a commitment and generates
CUD recommendations on a monthly basis.</p>
<p>For more information about how CUD recommendations are generated, what resource
types are supported, and how to use recommendations to purchase commitments, see
<a href="https://docs.cloud.google.com/docs/cuds-recommender">Get recommendations for committed use discounts (CUDs)</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Security</h3>
<p>If the parent project for a Cloud Storage bucket changes, a log sink
stops routing log entries to that bucket. For more information about error
messages and recovery options, see
<a href="https://docs.cloud.google.com/logging/docs/export/troubleshoot#errors_exporting_to_cloud_storage">Errors routing to Cloud Storage</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Metrics Explorer can automatically break down a chart into a series of tiles,
with each displaying time-series data for a specific label key. This view helps
you identify spikes, dips, or trends that the aggregation settings might
otherwise hide.</p>
<p>To learn more, see
<a href="https://docs.cloud.google.com/monitoring/charts/breakdown-chart-by-labels">Break down a chart by labels</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/backup-recovery/backup-options">Choose your backup
option</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/backup-recovery/backup-options">Choose your backup
option</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>Customer-managed encryption key (CMEK) support for Cloud SQL enhanced backups is
generally available. You can protect your CMEK-enabled Cloud SQL instances
using Google Cloud Backup and DR Service.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/backup-recovery/backup-options">Choose your backup
option</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpluav3lua">Envoy Lua Filter</a>
is now available as a preview feature in the rapid release channel.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can create instances all at once in a regional
managed instance group (MIG) by using resize requests. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/about-resize-requests-mig">About resize requests in a MIG</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Resource-based committed use discount (CUD)
recommendations are available for GPUs, Local SSD disks, and premium operating
system (OS) licenses.</p>
<p>CUD recommendations provide insight into any additional commitments that you can
purchase to optimize the costs of the resources that you run. You can use these
recommendations and purchase commitments for resource usage that isn't covered
by commitments and is being charged at list prices. Google Cloud analyzes your
compute instance spending trends with and without a commitment and generates
CUD recommendations on a monthly basis.</p>
<p>For more information about how CUD recommendations are generated, what resource
types are supported, and how to use recommendations to purchase commitments, see
<a href="https://docs.cloud.google.com/docs/cuds-recommender">Get recommendations for committed use discounts (CUDs)</a>.</p>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced">Hyperdisk Balanced</a>
disks for Dataflow worker VMs. With Hyperdisk Balanced disks, you can provision
IOPS and throughput independently of disk size by using the <code>diskProvisionedIOPS</code>
and <code>diskProvisionedThroughput</code> pipeline options (Java SDK) or
<code>disk_provisioned_iops</code> and <code>disk_provisioned_throughput_mibps</code> pipeline options
(Python and Go SDKs). For more information, see
<a href="https://docs.cloud.google.com/dataflow/docs/guides/configure-worker-vm#disk-type">Disk type</a> and
<a href="https://docs.cloud.google.com/dataflow/docs/guides/configure-worker-vm#provisioned-performance">Provision IOPS and throughput</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Provisioned Throughput support for supervised fine-tuned Gemini 3 model inference.</strong></p>
<p>Provisioned Throughput can be used to assure supervised fine-tuned inference using the same quota. Supervised fine-tuned inference for Gemini 3 models incurs a higher burndown rate compared to base model inference. Learn more <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/supported-models#supervised-fine-tuned-model-support">here</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.43</strong></p>
<p>We've released version 4.43 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Calls to direct numbers display language selection in the call adapter</strong></p>
<p>When an agent receives a direct call, the call adapter now displays the language
that the caller chose during language selection.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/call-settings#direct-phone-numbers">Direct phone
numbers</a>.</p>
<h3>Feature</h3>
<p><strong>HubSpot: Control the display of CRM account fields and record fields in the
agent adapter</strong></p>
<p>You can now control how CRM account fields (contact and company) and record
fields (ticket and deal) appear in the agent adapter for HubSpot integrations.
This gives agents immediate access to important context such as VIP status,
account ownership, and ticket priority during live interactions.</p>
<p>Administrators: In the <strong>Settings <span aria-label="and then">&gt;</span> Developer Settings <span aria-label="and then">&gt;</span>
CRM <span aria-label="and then">&gt;</span> Agent Platform <span aria-label="and then">&gt;</span> HubSpot <span aria-label="and then">&gt;</span> Account
Lookup</strong> section, there are two new <strong>CRM Account Display Fields</strong> sections and
a new <strong>CRM Record Display Fields</strong> section.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/hubspot-lookups">HubSpot
lookups</a>.</p>
<h3>Feature</h3>
<p><strong>The chat API supports CSAT surveys</strong></p>
<p>You can now conduct customer satisfaction (CSAT) surveys using the chat API. You
can configure CSAT surveys at the global level and at the queue level.</p>
<p>Administrators: On the <strong>Settings <span aria-label="and then">&gt;</span> Chat</strong> page, there's a new <strong>Chat
API</strong> section.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/csat-chat-api#adding_translations_for_multiple_languages">CSAT in the chat
API</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where uploading a PDF document to a chat made the
conversation history unavailable during a session transfer or page refresh.</p></li>
<li><p>Fixed an issue where direct SMS chats didn't send termination notifications
at the end of the chat.</p></li>
<li><p>Fixed an issue where the after-hours voicemail greeting didn't play during
agent-to-agent call deflections.</p></li>
<li><p>Fixed an issue where SIP and IVR calls intermittently failed if the caller
disconnected before a virtual agent was assigned.</p></li>
<li><p>Fixed an issue where calls deflected to voicemail during after-hours were
incorrectly reported as errors in the <strong>All Call History</strong> report.</p></li>
<li><p>Fixed an issue where direct inbound calls were incorrectly deflected to
voicemail during an agent's available hours when agent deflections were
enabled.</p></li>
<li><p>Fixed an issue where inbound voice calls failed with an application error
during the initial lookup phase.</p></li>
<li><p>Fixed a Kustomer issue where Agent Assist transcripts were
delivered to the CRM as file attachments instead of timeline notes.</p></li>
<li><p>Fixed an issue where the <strong>In Progress</strong> banner and the <strong>Cancel</strong> button
didn't appear immediately after a virtual task assistant request was
initiated.</p></li>
<li><p>Fixed an issue where campaigns stayed in a paused state instead of
transitioning to a completed state after finishing.</p></li>
<li><p>Fixed a Deltacast issue where chats weren't routed correctly to available
agents when the company-wide concurrency setting was disabled but individual
agent limits were active.</p></li>
<li><p>Fixed an issue where supervisor monitoring and whisper features caused
system errors during call recording.</p></li>
<li><p>Fixed an issue where agents couldn't dismiss forwarded voicemails if the
source queue had been deleted.</p></li>
<li><p>Fixed an issue where Telnyx calls that ended normally didn't generate a
disconnect event, resulting in missing recordings, missing transcripts, and
calls appearing to still be active in the CCAI Platform portal.</p></li>
<li><p>Fixed an issue where consecutive IVR queue deletions caused performance
delays and timeout errors.</p></li>
<li><p>Fixed an issue where queue-level automatic wrap-up settings were
disabled without an end-user action.</p></li>
<li><p>Fixed an issue where the queue settings page displayed inconsistent whisper
announcement statuses and didn't play queue names during calls.</p></li>
<li><p>Fixed an issue where the <strong>Queues</strong> page displayed incorrect overcapacity
deflection settings when end-users navigated quickly between different
queues.</p></li>
<li><p>Fixed an issue where virtual agents attempted to fail over to a human agent
during outages even when no human agent was configured.</p></li>
<li><p>Fixed a Salesforce issue where initiating an outbound call from an active
case linked to a separate case assigned to a different user, incorrectly
overriding ownership of the second case.</p></li>
<li><p>Fixed a Kustomer issue where duplicate conversation records were created in
the CRM during calls.</p></li>
<li><p>Fixed a Kustomer issue where SMS chat sessions didn't create tickets in the
CRM.</p></li>
<li><p>Fixed an issue where underscores in an email address in a shortcut
were converted to double backslashes when an agent sent the email address to
an end-user.</p></li>
<li><p>Fixed an issue where deleting Twilio records caused unnecessary errors.</p></li>
<li><p>Fixed an issue where disabling the global CSAT setting prevented IVR surveys
from being offered to callers, even when the surveys were enabled for
specific queues.</p></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Knowledge Catalog connectors for importing metadata from Oracle and MySQL data
sources are available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>Knowledge Catalog connectors automatically extract metadata (technical,
operational, and business) from external data sources and import it into
Knowledge Catalog entry groups. You can schedule metadata import runs on a set
schedule.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/connectors">About database connectors</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/manage-connector-jobs">Manage connector configurations</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>Starting June 22, 2026, the following features will begin rolling out as part of Looker 26.10.</p>
<h3>Feature</h3>
<p>Now available in preview, model localization is supported for imported projects. By default, Looker uses the locale definitions from the importing project only, if the importing project has locale definitions. However, if you want to merge the locale definitions from an imported project with the locale definitions of the importing project, you can add the <code>import_locale_defs: yes</code> statement to the <code>localization_settings</code> parameter in your importing project's manifest file. See the <a href="https://docs.cloud.google.com/looker/docs/model-localization#model_localization_and_project_import">Localizing your LookML model</a> documentation page for more information.</p>
<h3>Feature</h3>
<p>Dashboard editors can now enable the <a href="https://docs.cloud.google.com/looker/docs/editing-user-defined-dashboards#preserve-dashboard-layout"><strong>Preserve desktop layout</strong></a> setting to preserve the layout of a dashboard when users view the dashboard in a smaller browser or on a mobile screen. Users can navigate the dashboard with a zoom slider that enlarges tiles, and they can <a href="https://docs.cloud.google.com/looker/docs/mobile-app-viewing-dashboards#viewing_new_dashboards_in_the_app">switch between desktop and mobile view</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/looker/docs/continuous-integration">Continuous Integration (CI)</a> suites can now be configured to <a href="https://docs.cloud.google.com/looker/docs/ci-create-suite#schedule-trigger">automatically run on a recurring schedule</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/finding-content#searching_for_saved_content">Enhanced search</a> feature is now generally available.</p>
<h3>Feature</h3>
<p>The character limit for descriptions on dashboards and Looks has been increased to 2,000 characters, giving content creators the ability to add comprehensive descriptions, operational definitions, and notes to their dashboards and Looks to ensure that viewers fully understand the data context.</p>
<p>This feature is available to any user with standard content editing rights (<a href="https://docs.cloud.google.com/looker/docs/organizing-spaces#folder_access_levels">Edit content access level</a> or <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_dashboards"><code>save_dashboards</code></a> or <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_looks"><code>save_looks</code></a> permissions).</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service"><strong>Self-service Explores</strong></a> feature has the following updates:</p>
<ul>
<li>You can now <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service#bq-table">upload data from a BigQuery database table to create a self-service Explore</a>. </li>
<li>Previously, on the Looker <a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore"><strong>Self-service Explores</strong> Admin page</a>, there was a single toggle to enable data uploads on the instance. If the <strong>Data Uploads</strong> toggle was enabled, and your Looker admin also <a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore#enable-apis">enabled the APIs to support Google Sheets uploads</a>, then data imports from Google Sheets were enabled on the instance. Starting in Looker 26.10, there is a separate toggle for <strong>Google Sheets data import</strong> to allow your Looker admin more granular control over the data uploads on the instance. Your Looker admin can't enable this toggle until after the Looker admin has enabled the the APIs to support Google Sheets uploads.</li>
</ul>
<h3>Feature</h3>
<p>Looker admins can now programmatically change the owner of dashboards, boards, and agents with the <a href="https://docs.cloud.google.com/looker/docs/reference/looker-api/latest">Looker API</a> by updating the associated user ID. This simplifies offboarding and content reassignment when users change roles or leave the organization.</p>
<p>When the owner of a dashboard, a board, or an agent is changed, new owners are automatically granted <a href="https://docs.cloud.google.com/looker/docs/organizing-spaces#folder_access_levels">Manage/Edit access</a> to transferred agents. Any existing <a href="https://docs.cloud.google.com/looker/docs/content-certification">certification badges</a> on transferred dashboards remain intact.</p>
<p>The API initiator must have <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#save_content"><code>save_content</code></a> and <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles#manage_spaces"><code>manage_spaces</code></a> access to the folder where the asset resides.</p>
<p>Transferring ownership of dashboards and boards doesn't automatically grant the new owner access to parent folders, models, or underlying Looks.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/filters-user-defined-dashboards#filters_as_tiles">Filters as tiles and tile-level filter context</a> feature lets you convert dashboard filters into draggable tiles on the dashboard canvas. A dashboard editor can then drag and arrange filter tiles on the dashboard canvas in the same way as other dashboard tiles. To enable this feature, a Looker admin must turn on the <strong>Filters as tiles and tile-level filter context</strong> setting on the <strong>Previews</strong> admin page.</p>
<p>In addition, viewers can now check which filters are applied to a specific visualization tile.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/google-map-options">Google Maps</a> enhancements feature adds the following features:</p>
<ul>
<li>Fully supported <a href="https://docs.cloud.google.com/looker/docs/google-map-options#3d_heatmap">vector maps</a> for rendering thousands of data points seamlessly that support tilt, rotation, and dynamic 3D extrusions to elevate visual storytelling at every zoom level.</li>
<li><a href="https://docs.cloud.google.com/looker/docs/google-map-options#dual-axis_map">Dual-axis metric comparison</a> that lets you analyze multiple business metrics simultaneously on a single map interface, using heatmaps and points to uncover spatial correlations without switching views.</li>
<li><a href="https://docs.cloud.google.com/looker/docs/google-map-options#layers_menu_options">Contextual and custom overlays</a> that enhance geographical analysis by layering live traffic, transit, or bicycle routes, with granular styling controls for tailored iconography, colors, and sizing.</li>
</ul>
<h3>Feature</h3>
<p>The <a href="custom-looker-visualization-gemini">Visualization Assistant</a> is now available in the <a href="https://docs.cloud.google.com/looker/docs/editing-visualizations-new-explore-experience#using_the_visualization_assistant_in_the_new_explore_experience">new Explore experience</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/gemini-expression-asst">Gemini Expression Assistant</a> preview feature has been updated to increase performance.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#kpi_visualization"><strong>KPI Visualization</strong> feature</a> replaces the <strong>Single Value</strong> chart option with the <strong>KPI (Single Value)</strong> chart option. The new KPI (Single Value) chart option lets users access the following enhanced styling options for single value visualizations:</p>
<ul>
<li>Adding secondary visualizations: Users can add a sparkline or bar chart within a visualization to show trends or distributions that are related to the primary KPI.</li>
<li>Showing enhanced comparisons: Users can specify and compare a primary value against any other measure in an Explore query, using data from the first row, second row, last row, or totals row.</li>
<li>Accessing improved styling options: Users have more control over the appearance of the visualization, including the background color of the tile and the alignment of the values.
This feature is disabled by default. <a href="https://docs.cloud.google.com/looker/docs/kpi-single-value-options">Learn more about the new KPI (Single Value) Visualization</a>.</li>
</ul>
<h3>Change</h3>
<p>Looker dashboard agents are now included in the embedded Looker experience. Embed users with the <a href="https://docs.cloud.google.com/looker/docs/signed-embedding#permissions">appropriate permissions</a> can see dashboard agents on all the embedded dashboards that they have access to.</p>
<p><a href="https://docs.cloud.google.com/looker/docs/embedding">Learn more about how to configure an embedded dashboard for embed user visibility</a>.</p>
<h3>Change</h3>
<p>Conversational Analytics data agents that are <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#publish-data-agents">published to Gemini Enterprise</a> now support visualizations in their conversations.</p>
<h3>Change</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#granular-dashboard-sizing">Granular Dashboard Sizing preview feature</a> is now enabled by default.</p>
<h3>Change</h3>
<p>The dashboard summary feature can now be enabled separately from dashboard data agents. This feature is disabled by default. When this feature is enabled, a <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards#dashboard-summaries">dashboard summary</a> is generated automatically at the top of the dashboard data agent conversation. To enable this feature, a Looker admin must turn on the <strong>Enable Dashboard Summary</strong> feature on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Now available in preview, enhanced observability metrics, including engagement and token usage data, are available for Conversational Analytics on the <a href="https://docs.cloud.google.com/looker/docs/system-activity-dashboards#conversational-analytics">Conversational Analytics System Activity dashboard</a>. To enable this feature, a Looker admin must turn on the <strong>Conversational Analytics Observability</strong> setting on the <strong>Previews</strong> admin page.</p>
<h3>Breaking</h3>
<p>When you update the Gemini Enterprise instance that is connected to Looker, any <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#publish-data-agents">data agents that you published</a> to the previous Gemini Enterprise instance will be unpublished. You can still access these data agents in Looker, but you must re-publish them to the new Gemini Enterprise instance before you can chat with those agents in Gemini Enterprise.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Change</h3>
<p>Image scanning is available in the following cloud regions:</p>
<ul>
<li><code>asia-southeast1</code></li>
<li><code>us-east4</code></li>
<li><code>us-west1</code></li>
</ul>
<p>For more information, see <a href="https://cloud.google.com/sensitive-data-protection/docs/locations#image-limitations">Locations that support image scanning</a>.</p>
<h3>Fixed</h3>
<p>Between July 2025 and June 2026, some <a href="https://docs.cloud.google.com/sensitive-data-protection/docs/metrics-reference#table-data-profile">table data
profiles</a> saved to BigQuery contained an incorrect
<code>1970-01-01</code> timestamp instead of <code>NULL</code> in <a href="https://docs.cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/organizations.locations.tableDataProfiles#TableDataProfile.FIELDS.expiration_time"><code>expiration_time</code></a>
for tables that don't expire. This issue has been fixed. New exports of table
data profiles show the correct expiration timestamps.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: RoCE VPC networks for VM instances support assigning alias IP
ranges to <code>MRDMA</code> vNICs. For more information about these features, see the
following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc/docs/rdma-network-profiles">RDMA network profiles</a></li>
<li><a href="https://docs.cloud.google.com/vpc/docs/alias-ip">Alias IP ranges</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 21, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_21_2026</id>
    <updated>2026-06-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_21_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p><strong>Scheduled Maintenance</strong> </p>
<p>CloudSQL will undergo a scheduled minor upgrade this Sunday, June 21, 2026.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.90 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Announcement</h3>
<p><strong>Scheduled Maintenance</strong> </p>
<p>CloudSQL will undergo a scheduled minor upgrade.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 20, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_20_2026</id>
    <updated>2026-06-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_20_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Shell</h2>
<h3>Change</h3>
<p>Cloud Shell no longer includes the Terraform CLI by default. Users can
<a href="https://docs.cloud.google.com/shell/docs/configuring-cloud-shell#environment_customization">customize their environment</a>
to install the CLI on environment startup, or
install the binary to their home directory to persist the install between
sessions.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_14_2026">Release 6.3.89</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 19, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_19_2026</id>
    <updated>2026-06-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_19_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1166">v1.16.6</h3>
<p>On June 19, 2026 we released an updated version of the Apigee hybrid software, v1.16.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use the Bigtable Studio explorer to search for all resources except for
authorized views and column families. For more information, see
<a href="https://docs.cloud.google.com/bigtable/docs/manage-data-using-console">Manage your data using Bigtable Studio</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 18, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_18_2026</id>
    <updated>2026-06-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_18_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">API Gateway</h2>
<h3>Change</h3>
<p><strong>Update to the API Gateway runtime architecture</strong></p>
<p>The API Gateway runtime architecture is being updated to improve its integration
with Google Cloud Platform and its services.</p>
<p>This update does not affect existing API Gateway features.
However, be aware of the following differences:</p>
<ul>
<li><p>Status code changes for <strong>gRPC</strong> API Gateways
<table>
<tr>
<th>Error</th>
<th>New status code</th>
<th>Previous status code</th>
</tr>
<tr>
<td>Quota exceeded</td>
<td><code>ResourceExhausted</code></td>
<td><code>Unavailable</code>
</td></tr>
<tr>
<td>Invalid API key</td>
<td><code>InvalidArgument</code></td>
<td><code>InternalError</code></td>
</tr>
</table></p></li>
<li><p>For 4xx client-side quota failures, API Gateway will now reject requests
(fail closed). This applies to both <strong>gRPC</strong> and <strong>OpenAPI</strong> API Gateways.</p></li>
</ul>
<p>If you experience any other differences in behavior due to this update, contact <a href="https://cloud.google.com/support-hub">Google
Cloud Customer Care</a>.</p>
<p><strong>Note</strong>: Rollouts of this release to production instances might take up to 4 weeks to complete
across all Google Cloud zones. Your instances might not be updated until the rollout is complete.</p>
<h2 class="release-note-product-title">Agent Registry</h2>
<h3>Announcement</h3>
<p>Agent Registry is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<p>The following are features available in Agent Registry for the GA launch stage:</p>
<ul>
<li><strong>API v1 and client libraries:</strong> The <code>v1</code> version of the Agent Registry API is available. Cloud client libraries are available in C#, Go, Java, Node.js, PHP, Python, and Ruby.</li>
<li><strong>A2A v1 support:</strong> Agent Registry supports Agent-to-Agent (A2A) protocol version <code>1.0</code>, letting you explicitly declare transport endpoints and bindings inside the <code>supportedInterfaces</code> array, in addition to the existing <code>0.3</code> schema support.</li>
<li><strong>Terraform support:</strong> Terraform scripts for Application Default Credentials (ADC) have graduated to General Availability. You can use Terraform to configure and manage your agents, MCP servers, endpoints, and bindings.</li>
</ul>
<p><strong>Known limitations:</strong></p>
<ul>
<li><strong>Access Transparency and Access Approval:</strong> <a href="https://docs.cloud.google.com/assured-workloads/access-transparency/docs/overview">Access Transparency</a> logs, which provide visibility into when Google personnel access your content, and <a href="https://docs.cloud.google.com/assured-workloads/access-approval/docs/overview">Access Approval</a> controls aren't available for Agent Registry configurations.</li>
<li><strong>Data Residency:</strong> If you configure the <a href="https://docs.cloud.google.com/organization-policy/restrict-locations">resource location constraint</a> in your organization policy, Agent Registry enforces the constraint when you register a resource. However, detective controls for data residency compliance reporting are limited.</li>
</ul>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 18th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for maintenance windows</a>.</p>
<p>If you set a preferred window for maintenance for your instance, and your instance version is
below <strong>1-17-0-apigee-9</strong>, your instance will be updated to <strong>1-17-0-apigee-9</strong> within the
next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.</p>
<aside class="note">Note: Instances that meet either of the following two criteria will <b>not</b> be updated:
<ul>
<li>Your instance has a DNS misconfiguration, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues">Known Issue 445936920</a>.</li>
<li>Your instance uses an Apigee Java Library that has been removed, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee release notes dated October 16, 2025</a>.</li>
</ul></aside>
<p>For more information on participating in scheduled maintenance windows, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance">Maintenance overview</a> and <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">Manage Apigee instance maintenance windows</a>.</p>
<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>Backup vault support for Cloud SQL instances encrypted with customer-managed encryption keys (CMEK) is generally available (GA), providing immutable and indelible storage with enforced retention. For more information, see <a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/sql/csql-backup">Back up Cloud SQL instances to a backup vault</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Change</h3>
<p>The Cloud Logging API adds support for the <code>ca</code> regional endpoint. For a
complete list of regional endpoints, see the
<a href="https://docs.cloud.google.com/logging/docs/reference/v2/rest?rep_location=global">REST reference pages</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL now supports minor version
<a href="https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html">8.0.46</a>.
To upgrade your existing instance to the new minor version, see
<a href="https://docs.cloud.google.com/sql/docs/mysql/upgrade-minor-db-version#manual-upgrade">Upgrade the database minor version</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Cloud SQL is integrated with <a href="https://ai.google.dev/aistudio">Google AI Studio</a>
to help you build full-stack applications that use a
<a href="https://docs.cloud.google.com/sql/docs/postgres/ai-assisted-coding-and-cloud-sql#cloud-sql-configuration-in-starter-tier">Cloud SQL for PostgreSQL developer edition</a>
instance as the database. You can enter natural language
prompts in the Google AI Studio to build applications backed by Cloud SQL and
add features such as authentication, search, and persistent data storage.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sql/docs/postgres/ai-assisted-coding-and-cloud-sql">Build vibe-coded applications using Google AI Studio and Cloud SQL</a>.</p>
<p>This feature is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h3>Feature</h3>
<p>The rollout of the following Cloud SQL for PostgreSQL
minor version and extension upgrades is complete:</p>
<p><strong>Minor versions</strong></p>
<ul>
<li>14.22 is upgraded to 14.23.</li>
<li>15.17 is upgraded to 15.18.</li>
<li>16.13 is upgraded to 16.14.</li>
<li>17.9 is upgraded to 17.10.</li>
<li>18.3 is upgraded to 18.4.</li>
</ul>
<p>The new maintenance version is <a href="https://docs.cloud.google.com/sql/docs/postgres/maintenance-changelog"><code>[PostgreSQL version].R20260319.07_04</code></a>.
To apply the new maintenance version, see
<a href="https://docs.cloud.google.com/sql/docs/postgres/self-service-maintenance">Perform self-service maintenance</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>You can collect, view, and analyze multimodal prompts and responses from
your agentic applications that use the LangGraph or Agent Development Kit (ADK)
frameworks. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/instrumentation/ai-agent-overview">Instrument generative AI applications</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/collect-view-multimodal-prompts-responses">Collect and view multimodal prompts and responses</a></li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Workflow agents (GA with allowlist)</strong></p>
<p>You can create, import, update, and use workflow agents in the Gemini Enterprise
web app. These agents are designed to execute a sequence of
steps or actions, which can include a mix of AI automation and human intervention, based on a
configured trigger.</p>
<p>This feature is available as a GA with allowlist. To access this feature,
contact your Google account manager. After your Google Cloud project is added to
the allowlist, a Gemini Enterprise administrator must turn on the <strong>Enable agent designer</strong>
toggle in the web app feature management settings to let users use it.</p>
<p>For more information, see:</p>
<ul>
<li><p><a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage web app
features</a></p></li>
<li><p><a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer-eap/workflow-agents">Workflow agents</a>
(You need to be on the allowlist to access the page.)</p></li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Agent Gateway in General Availability</strong></p>
<p>Agent Gateway is the networking component of the Gemini
Enterprise Agent Platform ecosystem. It secures and governs connectivity for
all agentic interactions, whether they occur between users and agents,
agents and tools, or among agents themselves.</p>
<p>For details, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview">Agent Gateway
overview</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Observability is generally available (GA)</strong></p>
<p>This release provides visibility into the performance, behavior, and health of deployed agents and Model Context Protocol (MCP) servers directly within the agent management workflow.</p>
<p>Key updates in this release include:</p>
<ul>
<li><strong>Default-On Tracing:</strong> OpenTelemetry tracing is now enabled by default for newly deployed Agent Development Kit (ADK) agents on Agent Engine, simplifying the observability setup process without requiring manual configuration.</li>
<li><strong>Storage Prioritization:</strong> Google Cloud Storage (GCS) is the default storage choice in the Google Cloud Console, instead of Cloud Logging. We recommend that you store your multimodal prompt and response payloads in a Cloud Storage (GCS) bucket. This solution provides robust support for large payloads and it enables fine-grained lifecycle management.</li>
<li><strong>Enhanced Tracing:</strong> Inspect step-by-step session execution and view directed acyclic graphs (DAGs) of trace spans.</li>
</ul>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/optimize/observability/overview">Observability overview</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/optimize/observability/traces">View agent traces</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/tracing">Set up tracing</a></li></ul>
<h3>Feature</h3>
<p>The Agent Identity API (<code>agentidentity.googleapis.com</code>) is
available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
This new API replaces the legacy IAM Connectors API
(<code>iamconnectors.googleapis.com</code>) for managing auth providers and agent
identities.</p>
<p>During the preview migration period, both APIs operate side-by-side. Existing
auth providers are automatically mirrored to the new V2 resource hierarchy
(<code>authProviders/</code>), allowing you to migrate your IAM policies, agent code, and
client applications without downtime.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>For Exadata Database Service on Exascale infrastructure and Base Database Service, Oracle Database@Google Cloud adds region <code>asia-northeast2</code> (Osaka, Japan).</p>
<p>For a list of supported locations, see <a href="https://docs.cloud.google.com/oracle/database/docs/regions-and-zones">Supported regions and zones</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>Security Command Center External Exposure is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a> for the
Security Command Center Premium tier. The service helps you manage and reduce your external
attack surface through automated asset discovery, Google Cloud network exposure
path validation, and active exploitability testing.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/detect-external-exposure">Detect exposed
resources</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 17, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_17_2026</id>
    <updated>2026-06-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_17_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can enable <a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation">autonomous embedding
generation</a> on new or existing
tables that you make with the <a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation#create_an_automatically_generated_embedding_column"><code>CREATE
TABLE</code></a>
or <a href="https://docs.cloud.google.com/bigquery/docs/autonomous-embedding-generation#add_an_automatically_generated_embedding_column_to_an_existing_table"><code>ALTER
TABLE</code></a>
statements. When you do this, BigQuery maintains a column of embeddings on the
table based on a source column. When you add or modify data in the source
column, BigQuery automatically generates or updates the embedding column for
that data.</p>
<p>This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>CUD dashboard redesign available (preview)</strong></p>
<p>The redesigned CUD dashboard is available in the Billing section of the
Google Cloud console. It provides a consolidated view of all your resource-based
and spend-based CUDs in a single place. The new design improves usability and
scalability, helping you find information faster.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/billing/docs/how-to/cuds-list-overview">View your commitments</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Feature</h3>
<p>When you <a href="https://docs.cloud.google.com/storage/docs/composing-objects">create composite objects</a>, you can
delete the temporary source objects as part of the composition process.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Create and manage skills (GA with allowlist)</strong></p>
<p>You can create, import, update, and use skills in the Gemini Enterprise
web app. Skills are reusable custom instructions that help the assistant
perform specific tasks.</p>
<p>This feature is available as a GA with allowlist. To access this feature,
contact your Google account manager. After your Google Cloud project is added to
the allowlist, a Gemini Enterprise administrator must turn on the <strong>Enable skills</strong>
toggle in the web app feature management settings to let users use it.</p>
<p>For more information, see:</p>
<ul>
<li><p><a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage web app
features</a>.</p></li>
<li><p><a href="https://docs.cloud.google.com/gemini/enterprise/docs/skills">Create and manage
skills</a> (You need to be on the allowlist to access the page.)</p></li>
</ul>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Gemini Enterprise app for Slack</strong></p>
<p>Gemini Enterprise administrators can integrate Gemini Enterprise with Slack to
deliver AI-powered answers and search directly to users in their Slack
workspace. Once integrated, users can interact with Gemini Enterprise through
direct messages, slash commands, and channel mentions to receive answers that
incorporate data from all connected data stores.</p>
<p>This feature is generally available (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-slack-app">Configure the Gemini Enterprise app for
Slack</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Memory Bank and Sessions global and multi-regional endpoints GA</strong></p>
<p>Memory Bank and Sessions support for multi-regional and global endpoints is now
in General Availability (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/agent-locations#multi-regional-and-global-endpoints">Supported locations for agents</a>. Note that
Customer-Managed Encryption Keys (CMEK) cannot be used if your Memory Bank
or Sessions instance is configured to use the global endpoint.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>We are experiencing a delay preventing patch releases for GDC software
only for VMware. We are working diligently to resolve this issue. We will post
updates here with more information as it becomes available.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Change</h3>
<p><strong>Auto-collapse setting for the query editor</strong></p>
<p>You can now configure the query editor to automatically collapse after you run
a search, maximizing the screen space available for viewing your search results.
By default, the query editor remains expanded.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#CollapsequeryEditor">Configure query editor behavior</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p><strong>Secret Manager</strong>: Version 1.0</p>
<ul>
<li>New <strong>Secret Manager</strong> integration.</li>
</ul>
<h3>Change</h3>
<p>Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a>
for the following integrations:</p>
<ul>
<li><p><strong>AlienVault USM Appliance</strong>: Version 29.0</p></li>
<li><p><strong>AlienVaultTI</strong>: Version 15.0</p></li>
<li><p><strong>Arcsight</strong>: Version 46.0</p></li>
<li><p><strong>Axonius</strong>: Version 8.0</p></li>
<li><p><strong>BMC Helix Remedyforce</strong>: Version 18.0</p></li>
<li><p><strong>Cisco AMP</strong>: Version 24.0</p></li>
<li><p><strong>EasyVista</strong>: Version 8.0</p></li>
<li><p><strong>Mandiant</strong>: Version 10.0</p></li>
<li><p><strong>Office 365 Management API</strong>: Version 11.0</p></li>
<li><p><strong>SCCM</strong>: Version 22.0</p></li>
<li><p><strong>SonicWall-Beta</strong>: Version 9.0</p></li>
<li><p><strong>Stellar Cyber Starlight</strong>: Version 19.0</p></li>
<li><p><strong>Symantec Email Security.Cloud</strong>: Version 6.0</p></li>
<li><p><strong>Twilio</strong>: Version 16.0</p></li>
<li><p><strong>XForce</strong>: Version 20.0</p></li>
<li><p><strong>Zabbix</strong>: Version 17.0</p></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 86.0</p>
<ul>
<li><p>Fixed an issue where the connector would idle or hang on heartbeats instead of 
breaking early when <code>nextPageToken</code> or <code>nextPageStartTime</code> is received, and 
updated ontology mapping in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 29.0</p>
<ul>
<li><p>Updated host name extraction logic in the raw payload in the following 
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Change</h3>
<p><strong>Auto-collapse setting for the query editor</strong></p>
<p>You can now configure the query editor to automatically collapse after you run
a search, maximizing the screen space available for viewing your search results.
By default, the query editor remains expanded.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#CollapsequeryEditor">Configure query editor behavior</a>.</p>
<h2 class="release-note-product-title">Memorystore for Redis</h2>
<h3>Feature</h3>
<p>Memorystore for Redis supports the <a href="https://docs.cloud.google.com/products#product-launch-stages">General Availability</a>
of the following health issues:</p>
<ul>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/expensive-commands"><strong>Expensive commands</strong></a>:
resolve performance issues that are associated with using Redis commands that
are resource-intensive (expensive).</li>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/high-resource-utilization"><strong>High resource utilization</strong></a>:
resolve issues that are associated with instances not performing optimally.</li>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/maintenance-policy-not-set"><strong>Maintenance policy not set</strong></a>:
check whether users set maintenance windows for instances. If there's an optimal
time slot for the maintenance windows when there's low traffic, then the health
issue provides this slot.</li>
</ul>
<h2 class="release-note-product-title">Service Extensions</h2>
<h3>Feature</h3>
<p>Support for the <a href="https://docs.cloud.google.com/service-extensions/docs/callouts-overview#ext-authz"><code>ext_authz</code> Envoy gRPC API
protocol</a>
is now <a href="https://cloud.google.com/products#product-launch-stages">generally available
(GA)</a> for regional
external Application Load Balancers and regional internal
Application Load Balancers.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 16, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_16_2026</id>
    <updated>2026-06-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_16_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>AlloyDB integration with Knowledge Catalog is now generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<p>This integration provides a unified metadata view to simplify data governance and analysis. It includes near real-time synchronization and expanded metadata details, like primary and foreign keys.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/knowledge-catalog-integration">Integrate AlloyDB with Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1146">v1.14.6</h3>
<p>On June 16, 2026 we released an updated version of the Apigee hybrid software, v1.14.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Announcement</h3>
<p>Table Explorer behavior is moving to the <strong>Reference</strong> panel. This transition
will occur in July 2026 or later. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/table-explorer">Table Explorer</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>QueryData adds support for parameterized secure views (PSVs) to help secure
applications that use natural language queries. For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/secure-app-data-parameterized-secure-views-qd">Secure
and control access to application data</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Change</h3>
<p>For resource-based committed use discounts (CUDs), the default value of CUD
scope for most Cloud Billing accounts has changed from <strong>Project</strong> to
<strong>Billing account</strong>. If the CUD scope is set to <strong>Billing account</strong>, then
resource-based CUDs from a commitment are shared across all projects in that
account. If the CUD scope is set to <strong>Project</strong>, then resource-based CUDs from a
commitment are available to only the project in which you purchased that
commitment.</p>
<p>Depending on the Cloud Billing account's creation date and the active
commitments in that account, this change applies in the following way:</p>
<ul>
<li><strong>Cloud Billing accounts created on or after June 16, 2026</strong>: The
CUD scope is <strong>Billing account</strong> (CUD sharing enabled) by default.</li>
<li><strong>Cloud Billing accounts created before June 16, 2026</strong>:
<ul>
<li>If the account has <strong>no active resource-based commitments</strong> on
June 16, 2026, then the CUD scope has changed to <strong>Billing account</strong>
(CUD sharing enabled).</li>
<li>If the account has <strong>any active resource-based commitments</strong> on June 16,
2026, then the CUD scope remains unchanged and Google Cloud continues
to use your existing configuration.</li>
</ul></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/committed-use-discounts/share-resource-cuds-across-projects#cud-scope-configuration">Share resource-based CUDs across projects</a>.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Feature</h3>
<p>Support for the accelerator-optimized
<a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-vms">g4-standard-48 machine type</a>
for securely running AI and ML workloads is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>, with the
following specifications:</p>
<ul>
<li>5th Generation AMD EPYC Turin processor</li>
<li>AMD SEV</li>
<li>1 NVIDIA RTX PRO 6000 GPU</li>
</ul>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>Dataflow now supports NVIDIA RTX Pro 6000 GPUs. You can use this
GPU model to run your Apache Beam pipelines on Dataflow. RTX
Pro 6000 GPUs are recommended for large, medium, and small model inference
workloads. To configure your workers with this GPU model, set the accelerator
type to <code>nvidia-rtx-pro-6000</code>. For more information, see <a href="https://docs.cloud.google.com/dataflow/docs/gpu/gpu-support">Dataflow
support for GPUs</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: ServiceNow data store actions and federation</strong></p>
<p>The ServiceNow data store supports federation and assistant actions in
Gemini Enterprise.</p>
<p>You can connect a ServiceNow site to search and read incidents, change
requests, tasks, and knowledge base articles using natural language. You
can also perform actions, such as creating and updating incidents,
directly from the Gemini Enterprise app.</p>
<p>This feature is generally available (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/servicenow">Connect ServiceNow</a>.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.35.200-gke.66 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.35.200-gke.66 runs on Kubernetes v1.35.3-gke.400.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.200-gke.66:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where a transient or partial failure during node pool updates
could cause node taints or labels to become permanently stuck (stranded) on
worker nodes, even after you removed them from the NodePool custom resource
specification.
</li>
<li>Fixed an issue where, during the machine initialization phase, the
<code>etcd-events</code> pod read the stale data directory when it started
and attempted to reuse the old member ID to rejoin the cluster instead of the
new one. Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures the <code>/var/lib/etcd-events</code> directory is
cleared upon failure, and adds retry logic to <code>kubeadm-reset</code> to improve resiliency against transient API errors.
</li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane node
while waiting for the local API server to restart, causing nodes to temporarily
report an Unknown status and triggering transient routing disruptions (such as
503 Service Unavailable or ImagePullBackOff errors) for workloads scheduled on
those nodes.</li></ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine): Rollout of the <a href="https://docs.cloud.google.com/dataproc/docs/concepts/versioning/dataproc-version-clusters#supported-dataproc-image-versions">new sub-minor versions without pre-configured channels</a> will begin on June 22, 2026, delayed from the previously planned date of June 15, 2026 ETA.</p>
<h2 class="release-note-product-title">Secure Web Proxy</h2>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/secure-web-proxy/docs/policies-and-rules-overview#authorization-policies">authorization
policies</a>
to perform identity-based and content-based access control checks when
processing outbound traffic requests through Secure Web Proxy.</p>
<p>By <a href="https://docs.cloud.google.com/secure-web-proxy/docs/setup-authz-policies">configuring authorization
policies</a>, you can set rules for
your workloads to access external destinations. You can also use these
authorization policies to delegate complex authorization decisions to identity
and content-scanning services like Service Extensions. This feature is
supported in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/secure-web-proxy/docs/use-frontend-mtls-with-swp">integrate frontend mutual TLS (mTLS) with
Secure Web Proxy</a> to boost
the security of your applications and workloads.</p>
<p>With this integration, you can use validated client identities in
Secure Web Proxy <a href="https://docs.cloud.google.com/secure-web-proxy/docs/policies-and-rules-overview#authorization-policies">authorization
policies</a>
to enforce granular access control for outbound traffic. This feature is
supported in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 15, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_15_2026</id>
    <updated>2026-06-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_15_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AI Hypercomputer</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Before you create Spot VMs, you can view the real-time
availability, estimated uptime, historical preemption rate, and pricing for a
specific machine type and location. This information helps you maximize the
chances of successfully creating Spot VMs and choose the
configuration that best fits your workload needs and budget. For more
information, see <a href="https://docs.cloud.google.com/ai-hypercomputer/docs/consumption-models#spot">Use Spot</a>.</p>
<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>The Database Insights remote Model Context Protocol (MCP) server now supports
the following advanced query insights tools for AlloyDB for PostgreSQL:</p>
<ul>
<li><code>get_advanced_aggregated_query_stats</code></li>
<li><code>get_advanced_aggregated_wait_event_stats</code></li>
<li><code>get_advanced_time_series_query_stats</code></li>
<li><code>get_advanced_time_series_wait_event_stats</code></li>
<li><code>get_index_recommendations</code></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/reference/mcp/databaseinsights/mcp/index">Database Insights remote MCP server</a>.</p>
<h2 class="release-note-product-title">Anti Money Laundering AI</h2>
<h3>Announcement</h3>
<p>New minor engine versions released for the commercial line of business within the <code>v004.009</code> and <code>v004.010</code> version lines. These versions extend support for the major engine version and include no significant changes compared to the previous minor versions.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>Use Gemini Cloud Assist to analyze your SQL queries and receive
recommendations to <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#optimize-query">optimize query performance in BigQuery</a>.
This feature is available to customers who use BigQuery editions.
This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Issue</h3>
<p>Support for configuring daily token quotas for BigQuery generative AI
functions has been temporarily disabled. We are working to restore this
feature as soon as possible.</p>
<h3>Feature</h3>
<p>You can resize the width of table columns in BigQuery Studio for
BigQuery listings such as datasets, repositories, job history,
and connections. To resize a column, hover over the column divider and drag it
to your preferred width.</p>
<h3>Feature</h3>
<p>You can use Gemini Code Assist directly within the BigQuery <strong>Jobs explorer</strong>,
<strong>Job details</strong>, <strong>Job history</strong>, and <strong>Capacity management</strong> pages to help you
troubleshoot and analyze performance issues. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/admin-jobs-explorer#get-job-details">Troubleshoot job
performance</a>. This feature
is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Blockchain Node Engine</h2>
<h3>Announcement</h3>
<p><strong>Limited support for Blockchain Node Engine</strong></p>
<p>Starting June 15, 2026, Blockchain Node Engine will enter a period of limited support.</p>
<ul>
<li><p>New node creation in Blockchain Node Engine and provisioning of new Blockchain RPC endpoints will be disabled.</p></li>
<li><p>Existing nodes and endpoints will continue to function and receive critical updates until the final shutdown date.</p></li>
<li><p>We recommend migrating your workloads to our partner, <a href="https://www.quicknode.com/gcp-node-migration"><strong>Quicknode</strong></a>, to avoid service disruption.</p></li>
</ul>
<p>For more information, see the <a href="https://docs.cloud.google.com/blockchain-node-engine/docs/migrate-to-quicknode.md">migration guide</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>New filters and group-by options available in Cloud Billing Reports</strong></p>
<p>Cloud Billing has added two <strong>filters</strong> to the <strong>Billing Reports</strong>
page to help you analyze and understand your costs:</p>
<ul>
<li><p><strong>Products</strong>: Google Cloud
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-products">Products</a>
consist of a group of SKUs (potentially from more than one
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-services">Google Cloud <em>Service</em></a>)
that work together and are sold as a single service, sometimes referred to as
a <em>logical</em> product family or a subscription service. Examples include
Gemini Enterprise and Firebase App Hosting.</p></li>
<li><p><strong>Originating services</strong>: An
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-orig-services">Originating service</a>
is a Google Cloud service that causes usage in another service. For
example, Google Kubernetes Engine (GKE) can cause usage in Compute Engine. In
this use case, when you are viewing the Compute Engine usage and
costs, GKE is an originating service when it causes usage
in Compute Engine.</p></li>
</ul>
<p>You can also
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by"><strong>Group by</strong></a> the new filters, to
summarize your costs by the dimension you select.</p>
<ul>
<li><strong>Product</strong>: When you
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-product">group by <em>Product</em></a>,
the Report shows your costs and savings summarized by Product.</li>
<li><strong>Originating service &gt; Service</strong>: When you
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-orig-service">group by <em>Originating service &gt; Service</em></a>,
the Report shows your costs and savings summarized by Originating service.
In the <strong>report table</strong>, you can expand each row for an <em>Originating service</em>
to see your costs summarized by each <em>Service</em> that is associated with the
<em>Originating service</em>.</li>
</ul>
<p>Learn more about <a href="https://docs.cloud.google.com/billing/docs/how-to/reports">analyzing billing data and cost trends with Reports</a>.</p>
<p>Learn how to <a href="https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs">view Gemini Enterprise costs in Cloud Billing reports</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpcompressorv3compressor">Envoy Compressor Filter</a>
is now GA in the rapid release channel.</p>
<p>To ensure your <code>EnvoyFilter</code> compressor configuration is fully supported, see
<a href="https://docs.cloud.google.com/service-mesh/docs/migrate/modernize-envoyfilter-compressor">Modernize EnvoyFilter compressor configurations</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Before you create Spot VMs, you can view the following
  information for a specific machine type and location:</p>
<ul>
<li><p><strong>You can view the real-time obtainability and estimated uptime</strong>. This
information helps you maximize your chances of successfully creating
Spot VMs, as well as help ensure that your workload starts
and runs efficiently.</p></li>
<li><p><strong>You can view historical and current preemption rate and pricing</strong>. This
information helps you compare and choose the configuration that best fits
your workload needs and budget.</p></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability">View the availability of Spot VMs</a>
and
<a href="https://docs.cloud.google.com/compute/docs/instances/view-spot-preemption-price">View the preemption rate and pricing for Spot VMs</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-224-36_">cos-129-19506-224-36 <a id='"cos-arm64-129-19506-224-36"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/fac8e2b17485d0065f6f69f83ddb8eb0e9d9c55a
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.36/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19862-0-0_">cos-dev-133-19862-0-0 <a id='"cos-arm64-dev-133-19862-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ef0c067405ff6956b986d853c39c609e6d457228
">COS-6.18.35</a></td>
<td>v29.4.3</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19862.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.5.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.3.</p>
<h3>Change</h3>
<p>Allow overriding IMA policy from oem partition.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v702.</p>
<h3>Change</h3>
<p>On cchost boards, autoload IMA policy on boot.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71289 in the Linux kernel.</p>
<h3>Change</h3>
<p>Set static UUID for the stateful partition.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43245 in the Linux kernel.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.18.35.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/ek-cpu-balloon to v1.2.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46244 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker to v29.4.3, Upgraded app-containers/docker-test to v29.4.3, Upgraded app-containers/docker-cli to v29.4.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46274 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.7.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46316 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/gentoo-functions to v1.7.7.</p>
<h3>Security</h3>
<p>Fixed KCTF-def602e in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v702.</p>
<h3>Security</h3>
<p>Fixed KCTF-e5b31d9 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap-ng to v0.9.3.</p>
<h3>Security</h3>
<p>Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39819,CVE-2026-39823,CVE-2026-39825,CVE-2026-42499,CVE-2026-39817,CVE-2026-39820,CVE-2026-39826,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-56_">cos-117-18613-613-56 <a id='"cos-arm64-117-18613-613-56"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7ead0fd4c30a3ac938a51edf82fd36b526ffa21b
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.56/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/libusb to v1.0.30.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v702.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-56647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38584 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23272 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31527 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43492 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46244 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46274 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46289 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46294 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46306 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-101_">cos-125-19216-395-101 <a id='"cos-arm64-125-19216-395-101"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/19cc070c0f9a696f1ec666a1c12e685222e54963
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.101/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v702.</p>
<h3>Fixed</h3>
<p>Uprev sys-kernel/lakitu-kernel-6_12 to v6.12.92</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71289 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46160 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46244 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46274 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46283 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46289 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46294 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46306 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46316 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-def602e in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-177_">cos-121-18867-381-177 <a id='"cos-arm64-121-18867-381-177"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/0b06ec28c776324f21325b54d9c4c8e501b34301
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.177/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v702.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31527 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43492 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46244 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46274 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46289 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46294 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46306 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-def602e in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-python/pyjwt to v2.13.0. This fixes
CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.</p>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>Dataflow has updated and expanded its pipeline update features for
streaming jobs:</p>
<ul>
<li><strong>Automated stop-and-replace updates</strong>: You can perform automated,
declarative stop-and-replace updates to streaming jobs.</li>
<li><strong>Parallel updates with the same job name</strong>: When you perform automated
parallel updates, you can use the same job name for the new replacement job.</li>
<li><strong>Auto-cancel draining jobs</strong>: When performing parallel or stop-and-replace
updates, you can configure Dataflow to automatically cancel
the old job if it does not finish draining after a timeout you specify.</li>
<li><strong>Update strategy configuration</strong>: You can explicitly choose between a
parallel update (<code>update_strategy_parallel_job_update</code>) and a standard
in-place update (<code>update_strategy_in_place_update</code>) while keeping all other
configuration the same.</li>
<li><strong>Template upsert functionality</strong>: When launching pipelines from classic
templates, flex templates, Terraform, or Config Connector, you can use the
<code>create_or_update_job</code> experiment to enable automatic create-or-update
(upsert) behavior. If an active job with the specified name already exists,
it is updated. Otherwise, a new job is created.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-stop-replace">Automated stop and
replace</a>, <a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-parallel-updates">Automated
parallel pipeline
updates</a>, and
<a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#templates-create-or-update">Automatic create or update (upsert) for
templates</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: New data stores and support for new actions (Public Preview)</strong></p>
<p>The following data stores are available in Public Preview:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airops">AirOps</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airtable">Airtable</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/calendly">Calendly</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/dynamics365">Dynamics 365</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/freshservice">Freshservice</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/googlestitch">Google Stitch</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/intercom">Intercom</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/mailerlite">MailerLite</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohocrm">Zoho CRM</a></li>
</ul>
<p>Additionally, support for new actions is available for the following data
stores:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/smartsheet">Smartsheet</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/wrike">Wrike</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohoprojects">Zoho Projects</a></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source">Connect a third-party data source</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Observability settings for individual agents (Preview)</strong></p>
<p>You can now configure observability settings for individual agents in
Agent Designer employee-made agents. This allows you to monitor metrics in
Metrics Explorer and view trace results in Trace Explorer for specific
agents.</p>
<p>Observability settings for individual agents are configured inside the
agent-level settings. Previously, observability was only available at the
application level, which applies to the Core Assistant agent.</p>
<p>This feature is in Public Preview. For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-observability-settings">Manage observability settings</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advanced reporting dashboards 4.36</strong></p>
<p>We've released version 4.36 of the advanced reporting dashboards.</p>
<h3>Feature</h3>
<p><strong>New child queues filter option</strong></p>
<p>Dashboards that have the <strong>Queue Name</strong> filter now also have a <strong>Child Queues</strong>
checkbox. Select <strong>Yes</strong> if you want to include all child queues of the
specified queue. There's also a new <strong>Child Queues (Yes / No)</strong> filter available
in Explores that have the <strong>Queue Name</strong> filter.</p>
<h3>Feature</h3>
<p><strong>The Agent &amp; Queue Status (Live) Explore contains new real-time agent and queue metrics</strong></p>
<p>The <strong>Agent &amp; Queue Status (Live)</strong> Explore contains the following new metrics:</p>
<ul>
<li><p><strong>In Call</strong>: the number of agents currently on a call</p></li>
<li><p><strong>Available / Waiting</strong>: the number of agents available and waiting for the
next contact</p></li>
<li><p><strong>Contacts in Queue</strong>: the number of calls currently waiting in the queue</p></li>
</ul>
<h3>Feature</h3>
<p><strong>Link directly to CSAT scores in your CRM from the CSAT dashboards</strong></p>
<p>In the <strong>CSAT Interactions</strong> table of the <strong>CSAT - Calls</strong> and <strong>CSAT - Chats</strong>
dashboards, next to the <strong>Session ID</strong> numbers, links to the associated CSAT
scores in your CRM are now available. You can go directly to the CSAT scores
without needing to search for them in your CRM.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-csat">CSAT dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>Updates to the Real-time Queue Monitoring - Calls dashboard</strong></p>
<p>The <strong>Real-time Queue Monitoring - Calls</strong> dashboard now includes the following
metrics tiles:</p>
<ul>
<li><p><strong>Total Rolled Over Pending Callbacks</strong></p></li>
<li><p><strong>Total Rolled Over Completed Callbacks</strong></p></li>
<li><p><strong>Avg CSAT Calls</strong></p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-real-time-queue-monitor">Queue monitoring dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>Updates to the Queue Performance dashboards</strong></p>
<ul>
<li><p>The <strong>Queue Performance - Calls</strong> and <strong>Queue Performance - Chats</strong>
dashboards now include the following:</p>
<ul>
<li><p>A new <strong>Interaction Type</strong> filter</p></li>
<li><p>A new <strong>Interaction Type</strong> column in the <strong>Queue Detailed Table</strong></p></li>
</ul></li>
<li><p>The <strong>Queue Performance - Calls</strong> dashboard now includes the following
metrics tiles:</p>
<ul>
<li><p><strong>Total Rolled Over Completed Callbacks</strong></p></li>
<li><p><strong>Total Rolled Over Pending Callbacks</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Repeat contact data in the Queue Performance dashboards</strong></p>
<p>The <strong>Queue Summary Table</strong> of the <strong>Queue Performance - Calls</strong> and <strong>Queue
Performance - Chats</strong> dashboards now includes the following columns:</p>
<ul>
<li><p><strong>Total Repeat Contacts</strong></p></li>
<li><p><strong>Repeat Contact %</strong></p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-performance">Queue Performance dashboards</a>.</p>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where <strong>Repeat Contact %</strong> values in the <strong>Queue Summary
Table</strong> of the <strong>Queue Performance - Calls</strong> dashboard exceeded 100%.</p></li>
<li><p>Fixed an issue where the <strong>Date</strong> filter in Explores returned no results
when <strong>is on or after</strong> was set for an absolute date.</p></li>
<li><p>Removed the <strong>Total Logged in Time</strong> metrics tile from the <strong>Agent
Availability</strong> dashboard.</p></li>
<li><p>Fixed an issue where language labels were missing from the advanced
reporting dashboards.</p></li>
<li><p>Fixed an issue that occurred when filtering by chat ID in the <strong>All
Interactions - Chats</strong> dashboard. The wrong chat ID appeared in the
<strong>Virtual Agent Chats</strong> table.</p></li>
<li><p>Fixed an issue where disposition codes were missing or blank for outbound
calls in the <strong>Call Agent Metrics (Historical)</strong> dashboard.</p></li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Starting with Distributed Cloud software only for VMware version
1.33.0-gke.799, you must add <code>us.gcr.io</code> to your firewall allowlist to
create or upgrade advanced clusters.</p>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>You can use the error ID provided in permission error messages to help
troubleshoot access. Error IDs provide context for the error, including the
principal, resource, permission, and supported IAM conditions.
This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/iam/docs/permission-error-messages">Permission error messages</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 14, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_14_2026</id>
    <updated>2026-06-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_14_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.89 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 13, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_13_2026</id>
    <updated>2026-06-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_13_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Non-prioritized IoC Matching rules Category</strong></p>
<p>Google SecOps has introduced a new detection category, <em>Non-prioritized IoC Matching rules</em>, as part of the <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.</p>
<p>This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category">Non-prioritized IoC Matching rules category overview</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Non-prioritized IoC Matching rules Category</strong></p>
<p>Google SecOps has introduced a new detection category, <em>Non-prioritized IoC Matching rules</em>, as part of the <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.</p>
<p>This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category">Non-prioritized IoC Matching rules category overview</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_07_2026">Release 6.3.88</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 12, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_12_2026</id>
    <updated>2026-06-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_12_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview">BigQuery AI functions</a> can use
<a href="https://docs.cloud.google.com/bigquery/docs/work-with-objectref"><code>ObjectRef</code> values</a> directly as input,
without calling the <code>OBJ.GET_ACCESS_URL</code> function.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Change</h3>
<p>All <code>agent.googleapis.com/processes</code> metrics are retained for 24 months. For
more information, see <a href="https://docs.cloud.google.com/monitoring/quotas#data_retention_policy">Data retention</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can now create and query <a href="https://docs.cloud.google.com/sql/docs/postgres/parameterized-secure-views">parameterized secure views</a>
in Cloud SQL for PostgreSQL.</p>
<p>Parameterized secure views let you use PostgreSQL views with more granular
access control over your data. While you can issue a <code>GRANT</code> statement to control
whether a user can query a PostgreSQL view, a <code>GRANT</code> statement doesn't let you
control the data that the view returns based on the user who is making the
query.</p>
<p>To gain this level of control, use parameterized secure views. You can
define parameters such as a user ID or region within the view. When your
application queries the view, a user can provide values for these parameters,
which customizes the query results. Using parameterized secure views lets you
enforce "least privilege" access to help ensure that your users interact only
with the data that is relevant and authorized to them.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Security</h3>
<p>The following images are now rolling out for managed Cloud Service Mesh:</p>
<ul>
<li>Sidecar version 1.21.6-asm.36, is rolling out to the rapid release channel.</li>
<li>Sidecar version 1.20.8-asm.86 is rolling out to the regular release channel.</li>
<li>Sidecar version 1.19.10-asm.76 is rolling out to the stable release channel.</li>
</ul>
<p>These rollouts will preempt those <a href="#June_03_2026">previously announced on June 3, 2026</a>.</p>
<p>These patch releases contain the fix for the vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a></p>
<h3>Security</h3>
<p>Proxy version csm_mesh_proxy.20260423_RC03 for Gateway API on GKE clusters is
rolling out to all Managed Cloud Service Mesh release channels over the next
week.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise mobile app: General availability (GA) for Google Identity users</strong></p>
<p>The Gemini Enterprise mobile app is generally available (GA) for organizations using Google Identity as their identity provider. Users can access their agents, search enterprise data, utilize voice features, and perform interactive actions from iOS and Android devices.</p>
<p>With this release, administrators can display a configuration QR code on the web app homepage to enable user access by scanning the QR code. For organizations using Microsoft Entra ID, access to the mobile app is in GA with allowlist.</p>
<p>To learn more, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-mobile-app">Configure the mobile app</a> and <a href="https://docs.cloud.google.com/gemini/enterprise/docs/use-the-mobile-app">Use the mobile app</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.40</strong></p>
<p>We've released version 4.40 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue with Salesforce where virtual agent responses appeared out of
order in transcripts.</p></li>
<li><p>Fixed an issue where the advanced reporting dashboards didn't load.</p></li>
<li><p>Fixed an issue where PDF and audio attachments weren't visible to agents
after a chat transfer.</p></li>
<li><p>Fixed an issue where end-users were incorrectly placed on hold following a
cold transfer to a queue.</p></li>
<li><p>Fixed an issue where MP3 audio files for agent call deflections couldn't be
uploaded.</p></li>
<li><p>Fixed an issue where agents were automatically logged out due to inactivity
while still engaged in active calls or chats.</p></li>
<li><p>Fixed an issue where a bulk user upload with blank phone number columns
caused existing direct inbound phone numbers to become unassigned from agent
profiles.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1059000</li>
<li>1.34.8-gke.1126000</li>
<li>1.35.5-gke.1057000</li>
<li>1.36.0-gke.2459000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2458000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1868000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1492000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r23-security-updates">(2026-R23) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2681000</td>
<td>cos-117-18613-613-40</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_">cos-117-18613-613-40 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.2074000</td>
<td>cos-117-18613-613-40</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_">cos-117-18613-613-40 release notes</a></td>
</tr>
<tr>
<td>1.33.12-gke.1166000</td>
<td>cos-121-18867-381-161</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-161_">cos-121-18867-381-161 release notes</a></td>
</tr>
<tr>
<td>1.35.5-gke.1241000</td>
<td>cos-125-19216-395-55</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-55_">cos-125-19216-395-55 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2459000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1059000</li>
<li>1.34.8-gke.1126000</li>
<li>1.35.5-gke.1057000</li>
<li>1.36.0-gke.2459000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2458000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1868000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1492000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Search for cases using SIEM Search</strong></p>
<p>Google SecOps SIEM Search now provides robust capabilities for analyzing cases and case history alongside existing Unified Data Model (UDM) events and entities. This update allows security analysts to seamlessly correlate case details with other security telemetry within a single interface, streamlining workflows and accelerating incident response.</p>
<p>Key Highlights:</p>
<ul>
<li><p><strong>Unified Search Experience</strong>: Conduct searches across UDM events, entities, cases, and case history from a single SIEM Search interface.</p></li>
<li><p><strong>Correlate SIEM and SOAR Data</strong>: Effortlessly link case details and historical activities with security data, reducing context switching and improving investigation efficiency.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-and-search-case-history">Search cases and case history</a>.</p>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Investigate detections in Google SecOps Search</strong></p>
<p>Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the <strong>Alerts and Detections</strong> tab, providing a more holistic workflow for threat investigation.</p>
<p>For more details, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search">Investigate detections in Search</a>.</p>
<h3>Announcement</h3>
<p><strong>Asynchronous Search APIs for large datasets</strong></p>
<p>Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.</p>
<ul>
<li><strong>Non-blocking queries</strong>: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.</li>
<li><strong>Handle large result sets</strong>: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).</li>
<li><strong>Paginated results</strong>: View results efficiently in manageable pages.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api">Asynchronous Search APIs</a>
and <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources">Result limits for data sources</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Investigate detections in Google SecOps Search</strong></p>
<p>Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the <strong>Alerts and Detections</strong> tab, providing a more holistic workflow for threat investigation.</p>
<p>For more details, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search">Investigate detections in Search</a>.</p>
<h3>Announcement</h3>
<p><strong>Asynchronous Search APIs for large datasets</strong></p>
<p>Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.</p>
<ul>
<li><strong>Non-blocking queries</strong>: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.</li>
<li><strong>Handle large result sets</strong>: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).</li>
<li><strong>Paginated results</strong>: View results efficiently in manageable pages.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api">Asynchronous Search APIs</a>
and <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources">Result limits for data sources</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p>New Managed Airflow (Gen 2) environments created while the Restrict Endpoint
Usage organization policy is active now use regional endpoints for services
like Cloud Storage, Cloud Logging, Pub/Sub, and Data Lineage. For more
information, see
<a href="https://docs.cloud.google.com/composer/docs/composer-2/configure-restrict-endpoint-usage-environments">Configure environments with Restrict Endpoint Usage policy</a>.</p>
<h2 class="release-note-product-title">Media CDN</h2>
<h3>Feature</h3>
<p>The maximum cacheable object size for Media CDN can be increased up to 1 TiB. To
request a limit increase for your project, contact your Google support
representative. This feature is <strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/media-cdn/quotas">Quotas and limits</a>.</p>
<h3>Feature</h3>
<p>Media CDN lets you identify the country codes of the edge caches serving client
requests. This feature is <strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/media-cdn/docs/custom-headers#header-variables">Custom headers</a>.</p>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p>The ability to <a href="https://docs.cloud.google.com/policy-intelligence/docs/remediate-requests">remediate access
issues</a> with Policy Troubleshooter
is <a href="https://cloud.google.com/products#product-launch-stages">generally
available</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>Added support for inspecting and de-identifying batched content. You can now include a <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem#BatchContentItem">BatchContentItem</a></code> in your <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem">ContentItem</a></code> requests.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 11, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_11_2026</id>
    <updated>2026-06-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_11_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#administer_bigquery">monitor performance, analyze capacity, and optimize costs with Gemini Cloud Assist in BigQuery</a>.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Support for the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"><code>AI.KEY_DRIVERS</code> function</a>
is restored. You can use the
<code>AI.KEY_DRIVERS</code> function to identify segments of data that cause statistically significant changes to a summable metric.</p>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit v1.93.0 is available. This release introduces example
blueprints for GKE H4D deployments that use the <a href="https://docs.cloud.google.com/compute/docs/instances/about-flex-start-vms">flex-start provisioning
model</a>, a <a href="https://docs.cloud.google.com/compute/docs/instances/placement-policies-overview#about-compact-policies">compact placement
policy</a>
and integrated <a href="https://docs.cloud.google.com/tpu/docs/ml-diagnostics/overview">Google Cloud ML Diagnostics</a>.
This version also adds a Slurm High Availability controller script and upgrades Slurm
images from Rocky Linux 8 to Rocky Linux 9. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5770">Release
announcement on
GitHub</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>In an autoscaled managed instance group (MIG), you can configure the
stabilization period to manage how quickly the autoscaler deletes instances
after a decrease in the load. This configuration can help optimize costs or
maintain extra capacity based on your workload requirements. For more
information, see
<a href="https://docs.cloud.google.com/compute/docs/autoscaler/managing-autoscalers#configure_stabilization_period">Configure stabilization period</a>.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>The VMware Engine <a href="https://docs.cloud.google.com/vmware-engine/docs/concepts/node-types"><code>ve2</code> node type</a> is now available in the following
additional region:</p>
<ul>
<li>Mexico City (<code>northamerica-south1</code>)</li></ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 109.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Attach Playbook to Alert</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Knowledge Catalog now supports data profile scans for unstructured data
(such as PDFs in Cloud Storage) on existing BigQuery object tables.
This feature uses Vertex AI Gemini models to extract semantic insights,
including entities and relationships, from unstructured content.</p>
<aside class="note"><strong>Note:</strong><span> Data profile scans for unstructured data are currently available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a> using the
Dataplex REST API only. The cloud console and gcloud
workflows are not supported for this feature.</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/data-insights-unstructured-data">About unstructured data insights</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/use-data-profile-unstructured-data">Use data profile for unstructured data</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 10, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_10_2026</id>
    <updated>2026-06-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_10_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Assist</h2>
<h3>Change</h3>
<p>Agent Assist offers <a href="https://docs.cloud.google.com/agent-assist/docs/pgka">Proactive generative knowledge assist</a> V2 in GA. This version supports rich search context, multiple suggested queries, and granular control over triggering events.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>BigQuery continuous queries now support the following aggregation functions:</p>
<ul>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#array_agg"><code>ARRAY_AGG</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#string_agg"><code>STRING_AGG</code></a></li>
</ul>
<p>Support for these functions is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Multi-project access to Cloud Billing cost views available in
Preview</strong></p>
<p>In Cloud Billing accounts, multi-project access to usage costs lets
project owners, solution owners, developers, and other non-billing admins
see cost data for all of their authorized projects in a single view in the
Cloud Billing console.</p>
<p>The multi-project view uses a combination of Cloud Billing account
permissions and Google Cloud project permissions that let Cloud Billing
administrators and organization administrators jointly control access to
project-level cost data.</p>
<p>Using project-scoped Cloud Billing account permissions,
Cloud Billing administrators can control which solution owners can
view aggregated cost data in the Cloud Billing console.</p>
<ul>
<li>Learn more about <a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/overview">cost management for project owners</a>.</li>
<li>Learn how to <a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/setup-multi-project-access">set up multi-project access to costs views</a>.</li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Deprecated</h3>
<p>The configuration option to not enroll your cluster in a release channel (known
as <em>No channel</em>, formerly as <em>Static</em>) is now deprecated, and will be removed
on June 14, 2027. For any clusters not enrolled in a release channel, we
recommend that you <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/release-channels#existing-cluster">enroll the cluster</a>
before this date. After the removal date, GKE will enroll all remaining clusters
in the Stable channel. For more information about this deprecation and how you
can achieve the same functionality with release channels, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#no_channel">Clusters not
enrolled in a release channel</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Azure Security Center</strong>: Version 17.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connector:</p>
<ul>
<li><strong>Azure Security Center - Security Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 85.0</p>
<ul>
<li><p>Updated partial batch handling and added dynamic batch sizing to prevent 
timeout loops, refactored logging and added monitoring signals for process 
health, and pipeline states, and improved detections batch parsing and 
processing efficiency in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
<li><p><strong>Integration</strong>: Updated authentication flow mechanism.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud IAM</strong>: Version 20.0</p>
<ul>
<li><p>Updated Predefined Widgets in the following widgets:</p>
<ul>
<li><p><strong>List Roles</strong></p></li>
<li><p><strong>List Service Accounts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 64.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Azure Sentinel Incident Connector v2</strong></p></li>
<li><p><strong>Microsoft Sentinel Incident Tracking Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 32.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Defender ATP Connector</strong></p></li>
<li><p><strong>Microsoft Defender ATP Connector V2</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 42.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 19.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Security</strong>: Version 27.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Graph Office 365 Security and Compliance Connector</strong></p></li>
<li><p><strong>Microsoft Graph Security Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Protectwise</strong>: Version 7.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Get Pcap</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 28.0</p>
<ul>
<li><p>Fixed AttributeError during parsing of multiple host lists and added fallback 
hostname matching in the following actions:</p>
<ul>
<li><p><strong>List Endpoint Detections</strong></p></li>
<li><p><strong>Enrich Host</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 09, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_09_2026</id>
    <updated>2026-06-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_09_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Domains</h2>
<h3>Feature</h3>
<p>Organization Policy Service custom constraints are
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
for Cloud Domains. For more information, see
<a href="https://docs.cloud.google.com/domains/docs/custom-constraints">Use custom organization policies</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p><strong>1.29.4-asm.0 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>You can now download 1.29.4-asm.0 for in-cluster Cloud Service Mesh. It includes
the features of <a href="https://istio.io/latest/news/releases/1.29.x/announcing-1.29/">Istio 1.29.4</a> subject to the list of
<a href="https://docs.cloud.google.com/service-mesh/docs/supported-features-in-cluster">supported features</a>.</p>
<p>The following environment variables, labels, and annotations are not supported:</p>
<ul>
<li><code>PILOT_IGNORE_RESOURCES</code> and <code>PILOT_INCLUDE_RESOURCES</code></li>
<li><code>RetryIgnorePreviousHosts</code></li>
<li><code>omit_empty_values</code></li>
<li><code>PILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAY</code></li>
<li><code>MAX_CONNECTIONS_PER_SOCKET_EVENT_LOOP</code> with the value 1</li>
<li><code>PILOT_DNS_JITTER_DURATION</code></li>
<li><code>PILOT_DNS_JITTER_DURATION</code></li>
<li><code>ENABLE_NATIVE_SIDECARS</code> with the value true</li>
<li><code>PILOT_IP_AUTOALLOCATE_IPV4_PREFIX</code> and <code>PILOT_IP_AUTOALLOCATE_IPV6_PREFIX</code></li>
<li><code>PILOT_DNS_CARES_UDP_MAX_QUERIES</code></li>
<li><code>ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLS</code></li>
<li>'BLOCKED_CIDRS_IN_JWKS_URIS`</li>
<li><code>ENABLE_DEBUG_ENDPOINT_AUTH</code></li>
<li><code>DISABLE_TRACK_REMAINING_CB_METRICS</code></li>
<li><code>gateway.istio.io/tls-cipher-suites</code></li>
<li><code>fileFlushMinSizeKB</code> and <code>fileFlushInterval</code> settings in ProxyConfig</li>
<li><code>topology.istio.io/locality</code></li>
<li><code>statsCompression</code> ProxyConfig option</li>
<li><code>proxy.istio.io/config</code> annotation for metric compression overrides</li>
</ul>
<p>Istio's experimental feature to enable lazy subset creation of envoy statistics
is not supported.</p>
<p>The formatter option within the <code>spec.tracing[].customTags</code> field of the
Telemetry custom resource (telemetry.istio.io) is unsupported.</p>
<p>The <code>istiod_remote_cluster_sync_status</code> Prometheus gauge metric, exposed on the
<strong>Istiod control plane metrics endpoint</strong> (port 15014 <code>/metrics</code>), is not
supported.</p>
<p>The following are unsupported for proxyless gRPC clients:</p>
<ul>
<li><p>Configuring the <code>LEAST_REQUEST</code> load balancing policy within the
<code>spec.trafficPolicy.loadBalancer.simple</code> field of a <strong>DestinationRule</strong> custom
resource (<code>networking.istio.io</code>)</p></li>
<li><p>Configuring the <code>http2MaxRequests</code> circuit breaker within the
<code>spec.trafficPolicy.connectionPool.http.http2MaxRequests</code> field of a
<strong>DestinationRule</strong> custom resource (<code>networking.istio.io</code>)</p></li>
</ul>
<p>The <code>ENABLE_AUTO_SNI</code> flag is still supported to keep aligned with the legacy
behavior.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh version 1.29.4-asm.0 uses Envoy v1.37.4-dev.</p>
<h3>Announcement</h3>
<p>In-cluster Cloud Service Mesh 1.26 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see <a href="https://docs.cloud.google.com/service-mesh/docs/supported-features-in-cluster#supported_versions">Supported versions</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Security</h3>
<p>A vulnerability (CVE-2025-10263) about bypass of translation stages or GPT protections in some Arm core families
was discovered and has been addressed.
For more information, see the
<a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-036">GCP-2026-036 security bulletin</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_2">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Share agents with Google Groups</strong></p>
<p>End users can share agents created using Agent Designer with Google Identity
groups, provided an administrator has enabled this feature for the
Gemini Enterprise app.</p>
<p>This feature is generally available (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/share-agent">Share an agent</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Fable 5</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/fable-5">Claude Fable 5</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Mobile SDK for Android version 2.15.3 patch</strong></p>
<p>We've released version 2.15.3 of the Mobile SDK for Android.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where <code>UjetWebFormCallback</code> in the Android SDK lacked the
necessary methods to pass form data.</p></li>
<li><p>Fixed an issue where chat messages and content cards in the Mobile SDK
displayed out of order.</p></li>
<li><p>Fixed an issue where the Android SDK didn't start a new chat session after
the previous session ended.</p></li>
<li><p>Fixed an issue where customers couldn't customize the Android SDK to
display the timeout message to end-users.</p></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>UDM fields now show the sources of enrichment</strong></p>
<p>The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.</p>
<p>For more information, see: <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/data-enrichment#viewing_events">Viewing events</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>UDM fields now show the sources of enrichment</strong></p>
<p>The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.</p>
<p>For more information, see: <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/data-enrichment#viewing_events">Viewing events</a>.</p>
<h2 class="release-note-product-title">NetApp Volumes</h2>
<h3>Feature</h3>
<p>The backup capabilities for <a href="https://docs.cloud.google.com/netapp/volumes/docs/ontap/overview#about_ontap-mode">ONTAP-mode</a>
are generally available (GA). For more information, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/protect-data/about-backups">About backups</a>.</p>
<h3>Feature</h3>
<p>Google Cloud NetApp Volumes remote Model Context Protocol (MCP) server is
generally available. NetApp Volumes remote MCP server lets you manage storage
pools, volumes, backup vaults, backup policies, backups, and snapshots from
LLMs, AI applications, and AI-enabled development platforms. For more
information, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/deploy-use-cases/mcp/use-netapp-mcp">Use the NetApp Volumes remote MCP server</a>
and <a href="https://docs.cloud.google.com/netapp/volumes/docs/reference/mcp">NetApp Volumes MCP Reference</a>.</p>
<h2 class="release-note-product-title">Network Connectivity Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-connectivity/docs/network-connectivity-center/concepts/ncc-gateway-overview">NCC Gateway</a>
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>NCC Gateway lets you enable security functions, such
as third-party Security Service Edge (SSE), for cross-cloud network traffic.
You can use <a href="https://docs.cloud.google.com/secure-access-connect/docs/overview">Secure Access Connect</a> with
NCC Gateway to securely connect remote workforces to private
applications in Google Cloud, on-premises, or other cloud providers and to
public applications, like Palo Alto Networks Prisma Access.</p>
<p>For information about pricing, see
<a href="https://cloud.google.com/network-connectivity/pricing#ncc-gateway-pricing">NCC Gateway pricing</a>.</p>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/policy-intelligence/docs/deny-simulator-overview">Policy Simulator for deny policies</a>
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<h2 class="release-note-product-title">Pub/Sub Lite</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/pubsub/lite/docs/migrate-pubsub-lite-to-managed-service-for-apache-kafka">Pub/Sub Lite to Managed Service for Apache Kafka migration guide</a>
has been updated to use the latest client libraries and to use
<a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/kafka-connect-overview">Kafka Connect</a>
in Managed Service for Apache Kafka.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 08, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_08_2026</id>
    <updated>2026-06-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_08_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 8th, 2026, we released an updated version of Apigee (1-17-0-apigee-9).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>514384893</strong></td>
<td><strong>Security fix for Apigee.</strong> Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong></td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>512850756</strong></td>
<td>Added observability metrics for the OpenTelemetry trace export pipeline, reporting spans exported, export latency, batch size, and dropped spans.</td>
</tr>
<tr>
<td><strong>515039499</strong></td>
<td>Fixed an issue where OpenTelemetry trace export over HTTP could fail to authenticate when sent through a forward proxy that requires basic authentication.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1165">v1.16.5</h3>
<p>On June 8, 2026 we released an updated version of the Apigee hybrid software, v1.16.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">App Hub</h2>
<h3>Feature</h3>
<p>App Hub support for resources from <a href="https://docs.cloud.google.com/app-hub/docs/supported-resources">Memorystore</a> is now generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#analyze-lineage">analyze data lineage with Gemini Cloud Assist in
BigQuery</a>. This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now use Gemini Cloud Assist to
<a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#schedule_a_query">schedule queries</a>. This
feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can use the Google-developed, open source
<a href="https://docs.cloud.google.com/bigquery/docs/jdbc-for-bigquery">Java Database Connectivity (JDBC) driver for BigQuery</a>
to connect your Java applications to BigQuery. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can use custom constraints with Organization Policy to provide more
granular control over specific fields for some BigQuery sharing
resources. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/analytics-hub-custom-constraints">Manage Sharing data exchanges and listings using custom constraints</a>.
This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/control-access-to-resources-iam#deny_access_to_a_resource">IAM deny policies</a>
for BigQuery are now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can manage and limit the costs associated with BigQuery generative AI
functions by configuring <a href="https://docs.cloud.google.com/bigquery/docs/control-genai-costs">daily token quotas</a>.
Token-based cost management for BigQuery generative AI functions is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>FOCUS billing data export to BigQuery available in Preview</strong></p>
<p><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery">Cloud Billing data export to BigQuery</a>
now offers a FOCUS billing data export available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
The <a href="https://focus.finops.org/what-is-focus/" track-metadata-position="body" track-name="externalLink" track-type="tasks"><em>FinOps Open Cost and Usage Specification</em> (FOCUS)</a> 
is an open specification that defines clear requirements for technology billing
data generators to produce consistent cost and usage datasets. The Google Cloud
billing data export using the
<a href="https://focus.finops.org/focus-specification/">FOCUS specifications</a>
includes FOCUS columns up to
<a href="https://focus.finops.org/focus-specification/v1-2/">FOCUS version 1.2</a>.</p>
<p>For more information about the FOCUS billing data export to BigQuery, refer
to the following documentation:</p>
<ul>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-focus-setup">Set up FOCUS Cloud Billing data export to BigQuery</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-tables/focus-export">Structure of the FOCUS data export</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-tables/focus-export#conformance-report">FOCUS conformance report</a></li>
<li><a href="https://focus.finops.org/use-cases/?version=v1-2">Query examples for FOCUS use cases</a></li></ul>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL <a href="https://docs.cloud.google.com/sql/docs/mysql/optimize-high-memory-usage#enable-managed-buffer-pool">managed buffer pool</a>
is now generally available (<a href="https://cloud.google.com/products/#product-launch-stages">GA</a>).
Managed buffer pool helps you avoid out-of-memory events (OOMs) on your
Cloud SQL instance by reducing <code>innodb_buffer_pool_size</code> when memory usage is high.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Security</h3>
<p><strong>1.28.7-asm.4 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.28.7-asm.4 uses Envoy v1.36.8-dev.</p>
<h3>Security</h3>
<p><strong>1.27.9-asm.5 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/v1.27/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.27.9-asm.5 uses Envoy v1.35.12-dev.</p>
<h3>Security</h3>
<p><strong>1.26.8-asm.11 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/v1.26/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.26.8-asm.11 uses Envoy v1.34.14.</p>
<h3>Announcement</h3>
<p>The rollouts <a href="#June_03_2026">previously announced on June 3, 2026</a> have been
stopped. The following release will supersede them and include those patches
and the fix for the vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The Trace API supports regional endpoints. For a list of supported endpoints,
see the REST API reference pages:</p>
<ul>
<li><a href="https://docs.cloud.google.com/trace/docs/reference/v1/rest?rep_location=global">v1 REST reference</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/reference/v2/rest?rep_location=global">v2 REST reference</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Feature</h3>
<p>The workstation configuration creation page in the Google Cloud console has been optimized to make configuration creation faster and easier. Common machine settings are grouped into selectable machine presets, frequently used settings are consolidated on the <strong>Configuration essentials</strong> landing page, and a pending cluster with default settings is automatically provisioned when no cluster exists in your selected region.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>:
The <a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#supported_disk_types_for_c4d">C4D</a>
machine series supports Hyperdisk Balanced High Availability disks.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced-ha">About Hyperdisk Balanced High Availability</a>
and <a href="https://docs.cloud.google.com/compute/docs/disks/hyperdisk-perf-limits#hdbha-perf">Performance limits for machine series</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-125-19216-395-73_">cos-125-19216-395-73 <a id='"cos-arm64-125-19216-395-73"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9b2019e2a0a65bafcc7fb941120bfa3088ef8a59
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.73/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43492 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45837 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46061 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46062 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46072 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46076 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46108 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46128 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46129 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46139 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46159 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46177 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-224-16_">cos-129-19506-224-16 <a id='"cos-arm64-129-19506-224-16"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e06aec09f8bd1eace9b1d1adb0ec84899e9a05f5
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.16/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-162_">cos-121-18867-381-162 <a id='"cos-arm64-121-18867-381-162"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.162/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Announcement</h3>
<h3 id="gemini_35_flash_is_generally_available">Gemini 3.5 Flash is generally available</h3>
<p><a href="https://docs.cloud.google.com/gemini/docs/codeassist/gemini-3">Gemini 3.5 Flash</a>
is now generally available to Gemini Code Assist users in VS Code and IntelliJ.
You can use this model for <a href="https://docs.cloud.google.com/gemini/docs/codeassist/agent-mode">agent mode</a>,
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/chat-gemini">chat</a>, and
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/write-code-gemini#generate_code_with_prompts">code generation</a>.</p>
<h3>Announcement</h3>
<h3 id="gemini_35_flash_is_generally_available">Gemini 3.5 Flash is generally available</h3>
<p><a href="https://docs.cloud.google.com/gemini/docs/codeassist/gemini-3">Gemini 3.5 Flash</a>
is now generally available to Gemini Code Assist users in VS Code and IntelliJ.
You can use this model for <a href="https://docs.cloud.google.com/gemini/docs/codeassist/agent-mode">agent mode</a>,
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/chat-gemini">chat</a>, and
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/write-code-gemini#generate_code_with_prompts">code generation</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Gemini 3.5 Flash feature management toggle is no longer available after June 16, 2026</strong></p>
<p>Starting June 16, 2026, the Gemini 3.5 Flash feature management toggle is no longer available. This
change applies to the Global, US, and EU multi-regions.</p>
<aside class="note"><strong>Note:</strong><span> This is a correction to the date mentioned previously in the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/release-notes#June_05_2026">June 05,
2026 release note</a>.</span></aside>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.39</strong></p>
<p>We've released version 4.39 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue with Salesforce where cases weren't created when a virtual
agent connected to a call.</p></li>
<li><p>Fixed an issue where agents on teams with transfer restrictions couldn't
transfer chats to agents not assigned to a team.</p></li>
<li><p>Fixed an issue where agents who weren't available for chat transfers still
appeared in the transfer list, causing transfer attempts to fail.</p></li>
<li><p>Fixed an issue where the <strong>Submit</strong> wrap-up button didn't appear in the
call adapter after agents completed outbound calls.</p></li>
<li><p>Fixed an issue where an agent and caller could still hear each other after
the agent placed the caller on hold.</p></li>
<li><p>Fixed an issue in the agent desktop that occurred after an agent transferred
a call to a different queue. The agent desktop layout of the source queue
displayed to the receiving agent instead of the layout of the destination
queue.</p></li>
<li><p>Fixed an issue where the reporting for After Call Work (ACW) time was
artificially high for calls transferred to a third party.</p></li>
<li><p>Fixed an issue where overcapacity deflection settings interfered with
after-hours deflections, causing calls to be incorrectly queued.</p></li>
<li><p>Fixed an issue where the inactivity timeout didn't function as configured.</p></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Change</h3>
<p>Several API dependencies that aren't required by Managed Airflow (Gen 3) are
now phased out and must be enabled separately if you want to create
Managed Airflow (Gen 2) environments in a new project. This change was
<a href="https://docs.cloud.google.com/composer/docs/release-notes#June_16_2025">announced previously</a>.</p>
<p>The following API dependencies were phased out:</p>
<ul>
<li>artifactregistry.googleapis.com</li>
<li>cloudbuild.googleapis.com</li>
<li>container.googleapis.com</li>
<li>pubsub.googleapis.com</li>
</ul>
<p>The following API dependencies aren't phased out yet and are scheduled to be
detached from the Cloud Composer API in the future:</p>
<ul>
<li>sqladmin.googleapis.com</li>
</ul>
<p>Existing Managed Airflow (Gen 3) and Managed Airflow (Gen 2) environments in
projects where the Cloud Composer API is already enabled aren't impacted.</p>
<p>You can do the following:</p>
<ul>
<li>If your project has only Managed Airflow (Gen 3) environments, then you can
manually disable the listed APIs that were phased out.</li>
<li>If your project has Managed Airflow (Gen 2) environments, then we recommend
to keep these APIs enabled because disabling them might lead to environment's malfunction.</li>
<li>If you want to create Managed Airflow (Gen 2) environments in a new project,
you can enable the listed APIs manually or using a Google Cloud CLI
command. For more information, see
<a href="https://docs.cloud.google.com/composer/docs/composer-2/enable-composer-service#enable-gen-2-dependencies">Enable Managed Airflow (Gen 2) dependencies</a>.</li>
<li>If you use automation scripts to provision Managed Airflow (Gen 2)
environments, then make sure that the listed APIs are enabled in addition
to the Cloud Composer API.</li>
</ul>
<h2 class="release-note-product-title">Network Intelligence Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/">Cloud Network Insights</a> is in <strong>General Availability</strong>.</p>
<p>Cloud Network Insights monitors your network and web application performance
across multicloud and hybrid networks and provides visualization tools to help
identify and diagnose network issues.</p>
<p>The following additional features are included in this release:</p>
<ul>
<li><p><strong>Compute Engine VM Monitoring Points</strong>: <a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/add-monitoring-points#gce_vm">deploy a Monitoring Point</a> optimized for Google Cloud directly to your Google
Cloud infrastructure using Terraform.</p></li>
<li><p><strong>Connectivity Tests support</strong>: <a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/run-connectivity-tests">run Connectivity Tests</a>
from Cloud Network Insights to validate connectivity
between endpoints of some dual-ended network paths.</p></li>
</ul>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>The <code>OBJECT_TYPE/PERSON/SIGNATURE</code> infoType detector is available in <code>global</code> and the <code>asia</code>, <code>europe</code>, and <code>us</code> multi-regions. For more information about all infoTypes, see <a href="https://cloud.google.com/sensitive-data-protection/docs/infotypes-reference">InfoType detector reference</a>.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: Prefix and partial matching for filtering search queries (Preview)</strong></p>
<p>You can configure schema fields to support prefix matching and partial matching
in filter expressions:</p>
<ul>
<li><p>Prefix matching lets you filter search results based on whether a field value
starts with a specific string.</p></li>
<li><p>Partial matching lets you filter results based on whether the query contains
some of the words in the field value. Partial matching doesn't require a
perfect match like the <code>ANY</code> operator does.</p></li>
</ul>
<p>This feature is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/configure-field-settings">Configure field
settings</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: <code>EXISTS</code> filter for filtering search queries (Preview)</strong></p>
<p>You can use the <code>EXISTS</code> filter to filter search results for documents.
Specifying <code>EXISTS</code> for a field means that a document can only be returned in a
search request if the field has a value and that value is not the default.
This
filter is available for custom search and for media search. Use <code>EXISTS</code> with
other filters such as <code>ANY</code> and <code>IN</code> to create expressions to scope the
documents that can be returned in a search query.</p>
<p>This feature is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-search-metadata">Filter custom
search for structured or unstructured
data</a>, <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-website-search">Filter website
search</a>, and <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-media-search">Filter
media search</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 07, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_07_2026</id>
    <updated>2026-06-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_07_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.88 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 06, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_06_2026</id>
    <updated>2026-06-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_06_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Location Finder</h2>
<h3>Announcement</h3>
<p>Cloud Location Finder is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_31_2026">Release 6.3.87</a> is now available for all regions.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">General availability</a>
support for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_firebase_phone_number_verification">Firebase Phone Number Verification</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 05, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_05_2026</id>
    <updated>2026-06-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_05_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Data Fusion</h2>
<h3>Feature</h3>
<p>Cloud Data Fusion version 6.11.1.3 is
generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h3>Fixed</h3>
<p>Fixed in Cloud Data Fusion 6.11.1.3:</p>
<ul>
<li><p>Fixed an issue that caused pipeline preview runs to fail with an
<code>InaccessibleObjectException</code> when using certain plugins, such as
Cloud SQL for PostgreSQL
(<a href="https://cdap.atlassian.net/browse/CDAP-21212">CDAP-21212</a>).</p></li>
<li><p>Fixed an issue causing custom plugins to lose their logging context when
running in parallel pipeline branches, ensuring consistent log propagation
across both linear and parallel branched pipeline executions
(<a href="https://cdap.atlassian.net/browse/CDAP-21245">CDAP-21245</a>).</p></li>
<li><p>Fixed critical security vulnerabilities in CDAP
(<a href="https://cdap.atlassian.net/browse/CDAP-21250">CDAP-21250</a>).</p></li>
<li><p>Improved the latency of the <strong>List pipelines</strong> page
(<a href="https://cdap.atlassian.net/browse/CDAP-21244">CDAP-21244</a>).</p></li>
<li><p>Fixed an issue causing intermittent service unavailability after instance
upgrades (<a href="https://cdap.atlassian.net/browse/CDAP-21254">CDAP-21254</a>).</p></li>
</ul>
<h3>Change</h3>
<p>Changes in Cloud Data Fusion 6.11.1.3:</p>
<ul>
<li>Introduced a <code>deployStrategy</code> query parameter in the
<a href="https://cdap.atlassian.net/wiki/spaces/DOCS/pages/477560983/Lifecycle+Microservices#Create-an-Application">Deploy Application API</a>
to skip the re-deployment of an existing pipeline if its configuration hasn't
changed
(<a href="https://cdap.atlassian.net/browse/CDAP-21246">CDAP-21246</a>).</li>
</ul>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Custom dashboards can display trace data. You can view individual spans or
aggregated data. This feature is
<a href="https://docs.cloud.google.com/products#product-launch-stages">public preview</a>.
For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/display-traces-on-dashboards">Display trace data (Google Cloud console)</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/api-examples#dashboard-with-trace-data">Dashboard with trace data (API)</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Custom dashboards can display trace data. You can view individual spans or
aggregated data. This feature is
<a href="https://docs.cloud.google.com/products#product-launch-stages">public preview</a>.
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/display-traces-on-dashboards">Display traces on a custom dashboard</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Asana data store (Preview)</strong></p>
<p>The Asana data store is available in Public Preview in Gemini Enterprise.</p>
<p>You can connect an Asana account to search and read projects, workspaces,
teams, and tasks using natural language. You can also perform actions,
such as creating projects and tasks, directly from the Gemini Enterprise app.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/asana">Connect Asana</a>.</p>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Administrator control for Gemini 3.5 Flash</strong></p>
<p>As a reminder, effective June 9, 2026, the feature management toggle for
Gemini 3.5 Flash is no longer available. Gemini 3.5 Flash
is enabled by default for all users in the Gemini Enterprise app and cannot
be disabled.</p>
<p>This change applies to the Global, US, and EU multi-regions.</p>
<aside class="note"><strong>Note:</strong><span> The effective date has been extended by one day from the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/release-notes#May_26_2026">originally
announced schedule</a>.</span></aside>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.33.900-gke.90 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.33.900-gke.90 runs on Kubernetes v1.33.11-gke.100.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.33.900-gke.90:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where a transient or partial failure during node pool updates
could cause node taints or labels to become permanently stuck (stranded) on
worker nodes, even after you removed them from the NodePool custom resource
specification.
</li>
<li>Fixed an issue where, if a new control plane node failed to join a cluster
during bootstrapping or scaling (associated with installer Ansible runner job
failures), orphaned etcd memberships were not cleaned up, causing the existing
control plane's API server to restart repeatedly (flap) and blocking subsequent
retry attempts. </li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane
node while waiting for the local API server to restart, causing nodes to
temporarily report an Unknown status and triggering transient routing
disruptions (such as 503 Service Unavailable or ImagePullBackOff errors) for
workloads scheduled on those nodes.
</li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, when recreating a user cluster with a previously used
name (which commonly occurs during Terraform deployments or manual
reinstalls), cluster provisioning stalled indefinitely in the provisioning
state due to a missing k8s-health-check service account. The installer
ensures that the service account is created, eliminating the need to manually
create the service account as a workaround.</li></ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Deprecated</h3>
<p>Starting June 1, 2026, the Data Catalog service begins a phased shutdown. From this date onward, you might experience disruptions or a complete lack of access to Data Catalog APIs. Knowledge Catalog (formerly known as Dataplex Catalog) operates without impact.</p>
<p>For more information about migrating from Data Catalog to Knowledge Catalog, see <a href="https://docs.cloud.google.com/dataplex/docs/transition-to-dataplex-catalog">Transition from Data Catalog to Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> supports
data residency in the European Union (EU) for the Security Command Center Premium tier.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/data-residency-support">Planning for data
residency</a>.</p>
<h3>Change</h3>
<p>The following Security Command Center finding category names from AI Protection have
new names that clarify that AI Protection detects Gemini foundation models:</p>
<ul>
<li><code>VERTEX_AI_MODEL_DETECTED</code> changes to <code>GEMINI_MODEL_DETECTED</code>.</li>
<li><code>VERTEX_AI_MODEL_NOT_PROTECTED_BY_MODEL_ARMOR</code> changes to
<code>GEMINI_MODEL_NOT_PROTECTED_BY_MODEL_ARMOR</code>.</li>
</ul>
<p>For more information about AI Protection findings, see
<a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 04, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_04_2026</id>
    <updated>2026-06-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_04_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Anthos Config Management</h2>
<h3>Change</h3>
<p>Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>To view the instrumentation scope or the schema associated with a span, open the
<strong>Details</strong> view for the span and select the <strong>Metadata &amp; Links</strong> tab.
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/finding-traces#attributes-events">View attributes, log entries, and events</a>.</p>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit version 1.92.0 is available. This release introduces support for <a href="https://docs.cloud.google.com/tpu/docs/ml-diagnostics/overview">ML Diagnostics</a> on TPU machine types and <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/node-auto-provisioning">node auto-provisioning</a> on GKE clusters. The release also adds an optional infrastructure setup for inference gateways and compact placement for Slurm clusters by using the Dynamic Workload Scheduler (DWS) flex-start provisioning model. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5744">Release announcement on GitHub</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-121-18867-381-161_">cos-121-18867-381-161 <a id='"cos-arm64-121-18867-381-161"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.161/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-40_">cos-117-18613-613-40 <a id='"cos-arm64-117-18613-613-40"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8b4d5a73b054b07c3abedde85bd34343fffb9566
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.40/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h2 class="release-note-product-title">Document AI</h2>
<h3>Feature</h3>
<p>Custom extractor offers document validation and correction in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<p>This feature allows you to enhance extraction accuracy with validation rules
and document data using Common Expression Language (CEL) dialect.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/document-ai/docs/ce-common-expression-validation.md">CEL dialect for document
validation</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1000000</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000000</li>
<li>1.36.0-gke.2253000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1307000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2558000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1967000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1592000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1993000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r22-security-updates">(2026-R22) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.34.8-gke.1218000</td>
<td>cos-125-19216-395-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-7_">cos-125-19216-395-7 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2684000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1307000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1000000</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000000</li>
<li>1.36.0-gke.2253000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1993000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>GKE Gateway now supports frontend mTLS (client certificate validation). Frontend mTLS allows the Gateway to authenticate client-presented certificates. This feature is available for the following GatewayClasses:</p>
<ul>
<li><code>gke-l7-global-external-managed</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-rilb</code></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/secure-gateway#configure-frontend-mtls">Configure frontend mTLS for a Gateway</a>.</p>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2558000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1967000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1592000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/dataplex/docs/reference/rest/v1/projects.locations/lookupContext"><code>lookupContext</code></a> method to retrieve a pre-formatted bundle of data asset context optimized for interactive agentic workflows. This LLM-ready context helps to ground your agents in assessing and using data assets.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/retrieve-data-context">Retrieve context for data assets</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p><strong>Looker 26.10</strong> is expected to include the following changes, features, and fixes:</p>
<ul>
<li>Expected Looker (original) deployment start: <strong>Sunday, June 7, 2026</strong></li>
<li>Expected Looker (original) final deployment and download available: <strong>Sunday, June 21, 2026</strong></li>
<li>Expected Looker (Google Cloud core) deployment start: <strong>Sunday, June 7, 2026</strong></li>
<li>Expected Looker (Google Cloud core) final deployment: <strong>Sunday, June 21, 2026</strong></li>
</ul>
<h3>Fixed</h3>
<p>An issue has been fixed where clicking <strong>Save and Schedule</strong> on an Explore could fail to load the <strong>Schedule</strong> dialog in a Looker (Google Cloud core) instance. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where cross filters didn't properly appear in the right-aligned filter bar. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where attempting to download or schedule the <strong>Recent Login Failures</strong> tile on the <strong>User Activity</strong> System Activity dashboard could fail. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where users were unable to scroll dashboards when the filter bar was open. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where dragging a dashboard tile horizontally could cause the tile to expand beyond the browser window. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed for filters on <a href="https://docs.cloud.google.com/looker/docs/custom-calendars">custom calendar</a> fields that was causing a SQL error when the custom calendar <code>dimension_group</code> or the custom calendar <code>reference_date</code> had a non-timestamp <code>datatype</code> specified. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where configuring remote dependencies with custom SSH ports for on-premise Git repositories could fail. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where applying string matching filters (such as <code>Contains</code> or <code>Starts With</code>) with an empty value could generate incorrect filter SQL. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the labels that were specified in the <strong>PDT Override Additional JDBC Parameters</strong> field weren't being applied to BigQuery table creation jobs. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where changes to Markdown files weren't saved when you switched between <strong>Edit</strong> and <strong>Preview</strong> mode. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where running queries against derived tables in SQL Runner could cause Looker to return a 500 error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the right-aligned filter bar could become wide enough to require a scroll bar if a range slider filter was added. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where right-clicking in a drill-down menu during a cookieless embed session could incorrectly close the menu. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where retrieving all schemas for a Denodo connection could overload the database CPU. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <strong>Unsubscribe</strong> link could fail to appear in a scheduled report email. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the Advanced Vis Config editor would not recognize the <code>plotOptions.column.borderRadius</code> option. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where dashboard filters could fail to be updated from inactive to active color highlighting when certain types of date inputs were present. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where visualizations could overflow instead of shrinking when a tile or browser was resized. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>When you edit a visualization, the Advanced Vis Config editor can now override default theme border and padding styles. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where a join wouldn't be added to a query if the join was required by a measure that was excluded from an Explore. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where period-over-period (POP) measures of types <code>previous</code> and <code>difference</code> that were based on <code>count</code> and <code>sum</code> measures would incorrectly return null instead of zero when no data was available for the comparison period. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where filter suggestions on dashboard filters could incorrectly retain previous filter values. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where setting a field name or an Explore name in a LookML dashboard as a non-string datatype could cause the LookML validator to return a 500 error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <code>button group</code> dashboard filter type could display more than 30 options, cluttering the UI. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where moving a filter by dragging it could also inadvertently highlight text. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where some PDT settings were unavailable when you created a BigQuery connection by using the Quickstart flow in a Looker (Google Cloud core) instance. This feature now performs as expected.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/looker/docs/period-over-period">Period-over-period (PoP) measures</a> are now supported on connections to Trino databases.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>Memorystore for Valkey has additional <a href="https://docs.cloud.google.com/memorystore/docs/valkey/supported-monitoring-metrics#cloud-monitoring-node-metrics">node-level metrics</a> for Cloud
Monitoring. These metrics offer detailed insights into the health and
performance of individual nodes within an instance. You can use the metrics to
troubleshoot issues with the nodes to optimize their performance. The metrics
are available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud's Agent for SAP version 3.15</strong></p>
<p>Version 3.15 of Google Cloud's Agent for SAP is generally available (GA). This
version updates the libraries in the agent's
<a href="https://github.com/GoogleCloudPlatform/sapagent">GitHub repository</a> to address
vulnerabilities when you're building the agent from its GitHub source.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sap/docs/agent-for-sap/whats-new">What's new with Google Cloud's Agent for SAP</a>.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.1 is available for iOS. This version
fixes symbol collisions with libraries using Objective-C protos.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 03, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_03_2026</id>
    <updated>2026-06-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_03_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Node.js</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Ruby</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/slots#slot-autoscaling">BigQuery fluid scaling</a>, which provides
per-second billing with no minimum duration for autoscaling reservations,
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p><strong>1.28.7-asm.3 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.28.7-asm.3 uses Envoy v1.36.7-dev.</p>
<h3>Fixed</h3>
<p>Patch 1.28.7-asm.3 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.27.9-asm.4 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.27.9-asm.4 uses Envoy v1.35.10-dev.</p>
<h3>Fixed</h3>
<p>Patch 1.27.9-asm.4 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-31045">CVE-2022-31045</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2019-14993">CVE-2019-14993</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39155">CVE-2021-39155</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39156">CVE-2021-39156</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-23635">CVE-2022-23635</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p>The following images are now rolling out for managed Cloud Service Mesh:</p>
<ul>
<li>1.21.6-asm.32 is rolling out to the rapid release channel.</li>
<li>The regular release channel is being upgraded from 1.20 to 1.21.6-asm.32.</li>
<li>The stable release channel is being upgraded from 1.19 to 1.20.8-asm.80.</li>
</ul>
<h3>Fixed</h3>
<p>These patch releases contain the fixes for the following CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.26.8-asm.10 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.26.8-asm.10 uses Envoy v1.34.14.</p>
<h3>Fixed</h3>
<p>Patch 1.26.8-asm.10 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-31045">CVE-2022-31045</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2019-14993">CVE-2019-14993</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39155">CVE-2021-39155</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39156">CVE-2021-39156</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-23635">CVE-2022-23635</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can gradually create Flex-start VMs in a
managed instance group (MIG) as capacity becomes available. Unlike resize
requests for MIGs that wait for full capacity before creating VMs, this method
might create only a portion of your requested Flex-start VMs if
capacity is unavailable. The MIG creates the remaining VMs later as capacity
permits. Flex-start VMs run for up to seven days and help you
obtain high-demand resources, such as GPUs, at a discounted price.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/create-mig-with-flex-start-vms">Create a MIG that uses Flex-start VMs</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: DRZ and MLP compliance in the EU for Google NotebookLM Enterprise</strong></p>
<p>Gemini Enterprise is compliant with data residency (DRZ) and machine learning
processing (MLP) requirements in the EU for Google NotebookLM Enterprise
for adding sources and interacting with the sources (chat). However, the
Discover Sources feature and Studio features, such as audio overview, slide
deck, infographic, video overview, mind map, and reports, are not MLP
compliant.</p>
<p>For more information on location limitations, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations#notebooklm-limitations">NotebookLM
limitations</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.38</strong></p>
<p>We've released version 4.38 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Sort and filter emails</strong></p>
<p>Agents can now sort and filter emails by date in the email adapter.</p>
<p>User experience changes: The email adapter has the following new UI elements:</p>
<ul>
<li><p>A button to toggle between <strong>Oldest to newest</strong> and <strong>Newest to oldest</strong> in
the email list.</p></li>
<li><p>A <strong>Filter by Date</strong> list to filter by preset filters or by a configurable
date range.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/email-adapter#email-lists">Email
lists</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where Canadian French translations for notifications and
error messages were appearing in English.</p></li>
<li><p>Fixed an issue where the Alvaria WFM <strong>Agent Performance</strong> report was
exporting every minute instead of once daily.</p></li>
<li><p>Fixed an issue where the <strong>Agent Preferences</strong> table on the <strong>Agent
Availability</strong> dashboard didn't update when an agent modified their
availability preferences.</p></li>
<li><p>Fixed an issue that occurred when an agent manually changed their status to
<strong>Available</strong> before the point in time that automatic wrap-up was configured
to do so. In the <strong>Activity Timeline</strong> report, the status change was
mistakenly attributed to the system.</p></li>
<li><p>Fixed an agent desktop issue where clicking the <strong>Transfer</strong> button in an
SMS chat displayed an error instead of starting a transfer.</p></li>
<li><p>Fixed an issue where a delay in Salesforce task creation caused a lag in
updating the ticket ID on calls.</p></li>
<li><p>Fixed an issue where agents couldn't transfer SMS chats.</p></li>
<li><p>Fixed an issue where incoming chats were routed to newly signed-in agents
instead of to those who had been available the longest.</p></li>
<li><p>Fixed an issue where messages in the chat adapter's chat history weren't
labeled or aligned to distinguish agent messages from end-user messages.</p></li>
<li><p>Fixed an issue in the IVR <strong>Queue Menu Settings</strong> pane where the text input
field didn't appear when users selected <strong>Text-to-speech</strong>.</p></li>
<li><p>Fixed an issue in the SMS <strong>Queue Menu Settings</strong> pane where phone numbers
weren't appearing in the incoming and outbound <strong>Assigned Numbers</strong> fields.</p></li>
<li><p>Fixed an issue where the web SDK didn't load.</p></li>
<li><p>Fixed an issue where live transcripts and conversation summarization didn't
display in the agent desktop following an instance update.</p></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 28.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get PCAP Files For Events</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 23.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alerts Ticket</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 84.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get Detection Details</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 58.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Issue</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk Plus</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk PlusV3</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 67.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Incident</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 245.0</p>
<ul>
<li>Refactored internal code execution logic for the platform integration.</li></ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 275.6</p>
<ul>
<li>Refactored internal code execution logic and optimized core integration components.</li></ul>
<h3>Change</h3>
<p><strong>Microsoft Sentinel Incident Tracking Connector</strong>: Version 29.0</p>
<ul>
<li>Added the <code>Incident Creation Time Filter (days)</code> advanced parameter and optimized error handling logic.</li></ul>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p>You can use Policy Analyzer to visualize allow policy queries. This
can help you understand the relationship between identities, roles, permissions,
and resources within your resource hierarchy.</p>
<p>Policy Analyzer supports queries about agent identities. You can see
who can access an agent or what resources and agents a specific agent can reach.</p>
<p>These features are available in in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/policy-intelligence/docs/analyze-iam-policies">Analyze allow policies</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>Added support for inspecting and de-identifying conversational content. You can now include a <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem#Conversation">Conversation</a></code> in your <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem">ContentItem</a></code> requests.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">Preview stage</a> support
for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_workloadidentity">Workload Identity API</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 02, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_02_2026</id>
    <updated>2026-06-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_02_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can now configure a cooldown period to determine when autoscaling occurs
for your read pool instances. For more information, see
<a href="https://docs.cloud.google.com/alloydb/docs/instance-read-pool-scale#autoscale-read-pool">Scale an instance</a>.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 2nd, 2026, we released an updated version of Apigee Cassandra.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Apigee Cassandra security update</strong></td>
<td><strong>Security fix for Apigee Cassandra infrastructure.</strong> <p>This addresses the following vulnerabilities:<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39820">CVE-2026-39820</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499">CVE-2026-42499</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39836">CVE-2026-39836</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33814">CVE-2026-33814</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501">CVE-2026-42501</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33811">CVE-2026-33811</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39825">CVE-2026-39825</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39817">CVE-2026-39817</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39823">CVE-2026-39823</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39819">CVE-2026-39819</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39826">CVE-2026-39826</a></li></ul></p></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/remote-functions#create_a_remote_function">Remote functions</a> now
support a custom path in the endpoint URL. You can reuse a single Cloud Run
service for multiple BigQuery remote functions by specifying different path
suffixes on the same endpoint. This feature is <a href="https://cloud.google.com/products/#product-launch-stages">generally
available</a> (GA).</p>
<h2 class="release-note-product-title">Cloud Interconnect</h2>
<h3>Feature</h3>
<p>A single-region Critical production SLA for Cloud Interconnect is
<a href="https://cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<p>For workloads that require 99.99% availability within a single region, you can
now configure a single-region topology that achieves the Critical production SLA.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/tutorials/dedicated-creating-9999-availability">Establish 99.99% availability for Dedicated Interconnect</a>
or the
<a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/cci-overview">Cross-Cloud Interconnect overview</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>TLS post-quantum key exchange support is now available for
Application Load Balancers and external proxy Network Load Balancers.
Post-quantum key exchange is
essential for protecting today's traffic from future quantum computing
decryption risks (<em>harvest now, decrypt later</em> attacks).
With post-quantum key exchange enabled, the
load balancer uses post-quantum key exchange with clients that support TLS
1.3 and <code>X25519MLKEM768</code> key exchange.</p>
<p>This feature is rolling out in three phases:</p>
<ul>
<li><p>Phase 1 (Until October 2026): Post-quantum key exchange is not enabled by
default. Customers can elect to opt in and enable it using their SSL policy.</p></li>
<li><p>Phase 2 (October 2026 through October 2027): The feature is enabled by
default. Customers can elect to defer (opt out) if required.</p></li>
<li><p>Phase 3 (After October 2027): The feature is enabled by default,
and options to defer are no longer effective.</p></li>
</ul>
<p>We strongly encourage you to enable post-quantum key exchange now, even before
it is turned on by default. The opportunity to test this today will help you
verify that clients and any intermediate network devices can properly negotiate
post-quantum key exchange.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/post-quantum-tls#post-quantum-key-exchange">Post-quantum key exchange</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Support for <strong>Histogram</strong> widgets on custom dashboards is
<a href="https://docs.cloud.google.com/products#product-launch-stages">generally available</a>. These widgets extract
the most recent value from each time series, group those values into ranges,
and then provide a graphical representation of the result. Unlike tables or
other widgets that display the most recent values, <strong>Histograms</strong> display
information about the relative frequency of ranges of values.</p>
<p>This widget is one of several visualizations that you can use to display the
most recent values. For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/charts#add_histogram">Configure a histogram (Google Cloud console)</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/api-examples#dashboard_with_a_histogram_widget">Dashboard with an XyChart configured as a histogram (API)</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The create-observability bucket flow enforces organization policies with
constraints on resource locations. This flow also enforces policies that require
customer-managed encryption keys (CMEKs) and that restrict the projects that
store those keys. Your trace data is stored in an observability bucket.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/cmek">Support for CMEKs</a></li>
</ul>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>Datastream now offers a free tier for change data capture
(CDC) data processed from Google Cloud sources, such as
AlloyDB for PostgreSQL and Spanner. You get the first 100 GiB of
CDC data for free per billing account, per month.</p>
<p>For more information, see the <a href="https://cloud.google.com/datastream/pricing">Pricing</a> page.</p>
<h2 class="release-note-product-title">Filestore</h2>
<h3>Feature</h3>
<p>You can configure your Filestore instances to use Private Service Connect with NFSv3 or NFSv4.1 file system protocols and IPv4 or IPv6 address families to allow consumers access managed services privately from inside their VPC network. This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/filestore/docs/configure-psc">Create a Filestore instance with Private Service Connect</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Gemini 3 pro image (Nano Banana Pro) and Gemini 3.1 flash image (Nano Banana 2) for image generation</strong></p>
<p>Gemini 3.1 flash image (Nano Banana 2) and Gemini 3 pro image
(gemini-3.0-pro-image) are generally available (GA) in Gemini Enterprise app.</p>
<p>To make these models available to users in your Gemini Enterprise app, a
Gemini Enterprise administrator can manage them in the feature controls:</p>
<ul>
<li><p><strong>Gemini 3 pro image (Nano Banana Pro)</strong>: Turned off by default and is only available in the
Global region.</p></li>
<li><p><strong>Gemini 3.1 flash image (Nano Banana 2)</strong>: Turned off by default and is only available in the
Global region. If an administrator turned on this model during
its Public Preview, it remains turned on in GA in the
Gemini Enterprise app.</p></li>
</ul>
<p>For more information about feature controls, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Announcement</h3>
<p><strong>Updates to abuse monitoring and zero data retention documentation</strong></p>
<p>Documentation for abuse monitoring, zero data retention, and responsible AI has
been updated to align with the Advanced AI Safety Addendum. These updates
include new details regarding Advanced AI safety, partner-specific terms, and
request-response logging for models like Claude Mythos and Opus.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/abuse-monitoring">Abuse monitoring</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention">Zero data retention</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/responsible-ai">Responsible AI</a></li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>GKE is introducing the following changes to expand the capabilities of maintenance exclusions:</p>
<ul>
<li><strong>Per-node pool maintenance exclusions</strong>: Available in release channels, these replicate the functionality of disabling node pool auto-upgrades when your cluster isn't enrolled in a release channel.</li>
<li><strong>Extended "No upgrades" exclusion</strong>: The "No upgrades" default maintenance exclusion can now be up to 90 days long.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">Maintenance exclusions</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p><em>(Managed Airflow Gen 3)</em> You can now
<a href="https://docs.cloud.google.com/composer/docs/composer-3/connect-vpc-network#cloud-run-traffic">access Cloud Run endpoints restricted to internal ingress traffic</a>
through your environment's network attachment. This feature is available
through gcloud CLI beta commands and beta Cloud Composer API in all Managed
Airflow (Gen 3) versions.</p>
<h2 class="release-note-product-title">NetApp Volumes</h2>
<h3>Announcement</h3>
<p>Google Cloud NetApp Volumes Flex Unified service level is available with
limited performance in the following region:</p>
<ul>
<li>us-east5 (Columbus)</li>
</ul>
<p>For more information about limited performance regions, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/discover/service-levels#supported_regions_for_flex_unified_limited_performance">Supported regions for Flex Unified limited performance</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 01, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_01_2026</id>
    <updated>2026-06-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_01_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Assist</h2>
<h3>Feature</h3>
<p>Agent Assist offers <a href="https://docs.cloud.google.com/agent-assist/docs/summarization-with-custom-sections">summarization with custom sections 6.0</a> in GA. The 6.0 version is powered by <code>gemini-3.5-flash</code> and available in all Agent Assist <a href="https://docs.cloud.google.com/agent-assist/docs/regionalization">regions</a>.</p>
<h3>Change</h3>
<p>Agent Assist offers summarization autoevaluation with more rubrics for evaluating completeness. This update also explains the use of N/A in the overall performance view.</p>
<p><a href="https://docs.cloud.google.com/agent-assist/docs/summarization-autoeval-metrics">Summarization autoevaluation</a> is available in the following additional regions:</p>
<ul>
<li>us-east1</li>
<li>northamerica-northeast1</li>
<li>eu-west1</li>
<li>eu-west2</li>
<li>eu-west3</li>
<li>eu-west4</li>
<li>asia-southeast1</li>
<li>asia-northeast1</li>
<li>asia-south1</li>
<li>australia-southeast1</li>
</ul>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>The Facebook Ads connector for the BigQuery Data Transfer Service now supports
data transfers from the following Facebook Ads reports:</p>
<ul>
<li><code>AdInsightsMMM</code></li>
<li><code>Ads</code></li>
<li><code>AdCreatives</code></li>
<li><code>AdSets</code></li>
<li><code>Campaigns</code></li>
<li><code>AdImages</code></li>
<li><code>AdLabels</code></li>
<li><code>Businesses</code></li>
<li><code>CustomAudiences</code></li>
</ul>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>CUD Analysis is Generally Available</strong></p>
<p>CUD Analysis has reached general availability (GA). This tool supports the new
spend-based CUD model and provides a unified interface for customers to examine
both spend-based and resource-based CUDs. It offers a consolidated view of
Compute resources including the benefits of both resource-based and spend-based
CUDs.</p>
<p>You can use this tool to do the following:</p>
<ul>
<li><strong>Understand savings</strong>: Understand the financial impact of your commitments.</li>
<li><strong>Track key metrics</strong>: Track how effectively your commitments are being
used.</li>
<li><strong>Download data</strong>: Download a CSV file of your daily usage for offline
analysis and reporting.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/billing/docs/how-to/analyze-cuds">Analyze the effectiveness of your CUDs</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>A modernized, component-centric interface for Cloud Load Balancing is available
in <strong>Preview</strong>. This inaugural release provides an expanded perspective of load
balancing infrastructure, offering enhanced transparency into individual
component configurations.</p>
<p><a class="button button-primary" href="https://console.cloud.google.com/net-services/loadbalancing/advanced" target="console">Go to Cloud Console</a> </p>
<p>The key features of this release include the following:</p>
<ul>
<li><p><strong>Comprehensive resource inventory</strong>: A centralized, searchable, and sortable
management layer for granular resources—including forwarding rules,
target proxies, and TLSRoutes—facilitating detailed monitoring of
resource status and interdependencies.</p></li>
<li><p><strong>Interactive resource topology</strong>: A contextual visualization tool that maps
traffic flow from forwarding rules through proxies to backends, enabling
technical teams to efficiently analyze dependencies and accelerate issue
resolution.</p></li>
<li><p><strong>Integrated audit logging</strong>: Embedded audit logs within the console that
offer a unified module for monitoring and tracking
historical configuration changes.</p></li></ul>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>The details page for a span can display the call hierarchy of a trace by using a
directed acyclic graph (DAG). If you view an Application Monitoring dashboard
and explore the trace data that it displays, the flyout supports the DAG option.
If you open the <strong>Trace Explorer</strong> page and explore a span, the DAG option is
also available.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/docs/application-monitoring#explore-trace">Application Monitoring: Explore a trace</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/finding-traces#explore">Trace Explorer: Explore a trace</a></li>
</ul>
<h2 class="release-note-product-title">Cloud TPU</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Compute Engine supports Google's custom-developed
accelerator Tensor Processing Unit (TPU), providing a converged experience
across AI accelerators on Google Cloud. You can use the Compute Engine
instance API and managed instance group (MIG) API to create and manage TPU VMs.
You can perform standard VM configurations such as using a custom OS or
configure boot disk size. Compute Engine APIs support the creation and
management of TPU slices across all consumption options, enabling small-scale
experimentation and large-scale training and inference workloads.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/tpu/docs/tpus-in-compute-engine">TPU resources in Compute
Engine</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The details page for a span can display the call hierarchy of a trace using a
directed acyclic graph (DAG). One way to view a span's details is to open the
<strong>Trace Explorer</strong> page and select the span. The DAG view is also available for
some integrations. For example, if you view an Application Monitoring dashboard
and explore the trace data it displays, the flyout supports the DAG option.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/trace/docs/finding-traces#explore">Trace Explorer: Explore a trace</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/docs/application-monitoring#explore-trace">Application Monitoring: Explore a trace</a></li>
</ul>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Compute Engine supports the Google's
custom-developed accelerator Tensor Processing Unit (TPU), providing a converged
experience across AI accelerators on Google Cloud. You can use the
Compute Engine instance API and managed instance group (MIG) API to
create and manage TPU VMs. You can perform standard VM configurations such as
using a custom OS or configure boot disk size. Compute Engine APIs
support the creation and management of TPU slices across all consumption
options, enabling small-scale experimentation and large-scale training and
inference workloads.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/tpus/tpu-resources-in-compute-engine">TPU resources in Compute Engine</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: In a managed instance group (MIG), obtain the requested
number of virtual machine (VM) instances all at once by using bulk mode of the
target size policy. Using bulk mode helps you avoid partial VM provisioning in a
MIG. Bulk mode is particularly beneficial for batch workloads, such as high
performance computing (HPC) or distributed training, that require full capacity
before they can start. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/about-bulk-mode">About bulk mode</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-121-18867-381-148_">cos-121-18867-381-148 <a id='"cos-arm64-121-18867-381-148"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6c119c63599291cd468409254669be8082f330b9
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.148/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added dev-libs/mpdecimal and dev-python/gentoo-common.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Change</h3>
<p>Updated dev-lang/python to v3.11.15.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-55_">cos-125-19216-395-55 <a id='"cos-arm64-125-19216-395-55"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/d2ec5b118f6f5f38bb03d3079965327c76256ba1
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.55/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Allow overriding IMA policy from oem partition.</p>
<h3>Change</h3>
<p>On cchost boards, autoload IMA policy on boot.</p>
<h3>Change</h3>
<p>Set static UUID for the stateful partition.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-29_">cos-117-18613-613-29 <a id='"cos-arm64-117-18613-613-29"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4c8dd0401cd7357d11e75a8467d834167db03513
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.29/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated Python to v3.8.20.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-224-7_">cos-129-19506-224-7 <a id='"cos-arm64-129-19506-224-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ee5c0e72ce4f921969d64843af4f37b1e22a9738
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h2 class="release-note-product-title">Filestore</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/filestore/docs/use-filestore-mcp">Filestore remote Model Context Protocol (MCP) server</a> is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
The Filestore remote MCP server lets you create and manage Filestore instances from LLMs, AI applications, and AI-enabled development platforms.</p>
<h2 class="release-note-product-title">Firestore</h2>
<h3>Feature</h3>
<p>Support for searching for and managing your Firestore resources
using Knowledge Catalog, which is a platform for
storing, managing, and accessing your metadata. To learn more, see
<a href="https://cloud.google.com/firestore/native/docs/knowledge-catalog">View Knowledge Catalog insights</a>.</p>
<h2 class="release-note-product-title">Firestore with MongoDB compatibility</h2>
<h3>Feature</h3>
<p>Support for searching for and managing your Firestore resources
using Knowledge Catalog, which is a platform for
storing, managing, and accessing your metadata. To learn more, see
<a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/knowledge-catalog">View Knowledge Catalog insights</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Agent Designer migration to Gemini 3.5 Flash</strong></p>
<p>Agent Designer agents in the US and Global regions that previously migrated
from Gemini 2.5 Flash and Gemini 2.5 Pro to
Gemini 3.1 Pro have been migrated to Gemini 3.5 Flash. This
migration is automatic and requires no action.</p>
<p>To use a different model, edit your agent's settings using either
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/edit-agent#edit-using-chat">conversational chat</a>
or the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/edit-agent#edit-using-flow">flow builder</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Create and edit documents and slides in Canvas</strong></p>
<p>Canvas is a dedicated, interactive tool within the Gemini Enterprise
web app. It allows you to create and edit AI-generated documents and
presentations directly from your chats. You can then export these to Google
Workspace, Microsoft Office formats, and PDF.</p>
<p>A Gemini Enterprise administrator must turn on the feature so that users can
use it in the Gemini Enterprise app. For more information about feature
controls, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web
app</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/assistant-canvas">Create and edit documents and slides in Canvas</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Breaking</h3>
<p><strong>Gemini 2.0 Flash and Gemini 2.0 Flash-Lite are discontinued</strong></p>
<p>Gemini 2.0 Flash and 2.0 Flash-Lite are discontinued and are no longer
available. This includes both model serving and Provisioned Throughput. Use
Gemini 3.1 Flash-Lite, Gemma 4, or more recent Gemini releases.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>All 3-year (36-month) post-paid <code>ve2</code> <a href="https://docs.cloud.google.com/vmware-engine/docs/cud">committed use discounts (CUDs)</a> for Google Cloud VMware Engine purchased after May 31, 2026, will terminate on October 15, 2028. 3-year CUD pricing will apply, regardless of the actual term of the CUD. Additionally, 3-year pre-paid CUDs are no longer available; only 1-year pre-paid CUDs are available.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#May_28_2026">Manage access to preview features feature</a> has been rolled back.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>New SAP certification for operating system: RHEL 10.0 for SAP</strong></p>
<p>For use with SAP HANA and SAP NetWeaver on Google Cloud, SAP has certified the
operating system Red Hat Enterprise Linux (RHEL) 10.0 for SAP.</p>
<p>For more information about SAP-certified operating systems, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/sap/docs/sap-hana-os-support#quick_reference_table">Certified operating systems for SAP HANA</a></li>
<li><a href="https://docs.cloud.google.com/sap/docs/netweaver-os-support#quick_reference_table">Certified operating systems for SAP NetWeaver</a></li>
</ul>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>General Availability</strong>: <a href="https://docs.cloud.google.com/vpc/docs/about-composite-health">Composite Health for Private Service
Connect</a>, formerly known as Private Service
Connect health, lets service producers define health criteria for published
services, enabling automatic cross-region failover for consumers that access the
service by using Private Service Connect backends.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.1 is available for Android. This version
fixes an issue that caused package name collisions when
building projects using Android Gradle Plugin version 9.0 or higher.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 31, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_31_2026</id>
    <updated>2026-05-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_31_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>1Password Audit Events (<code>ONEPASSWORD_AUDIT_EVENTS</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS CloudFront (<code>AWS_CLOUDFRONT</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure AD Sign-In (<code>AZURE_AD_SIGNIN</code>)</li>
<li>Azure SQL (<code>AZURE_SQL</code>)</li>
<li>Azure Storage Audit (<code>AZURE_STORAGE_AUDIT</code>)</li>
<li>Barracuda WAF (<code>BARRACUDA_WAF</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>Cisco ACS (<code>CISCO_ACS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>Corelight (<code>CORELIGHT</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>Duo Administrator Logs (<code>DUO_ADMIN</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>Elastic Audit Beats (<code>ELASTIC_AUDITBEAT</code>)</li>
<li>Elastic Windows Event Log Beats (<code>ELASTIC_WINLOGBEAT</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Asset Inventory (<code>GCP_CLOUD_ASSET_INVENTORY</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Compute Context (<code>GCP_COMPUTE_CONTEXT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>GTB Technologies DLP (<code>GTB_DLP</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva (<code>IMPERVA_WAF</code>)</li>
<li>Imperva CEF (<code>IMPERVA_CEF</code>)</li>
<li>Imperva DRA (<code>IMPERVA_DRA</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Island Browser logs (<code>ISLAND_BROWSER</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Juniper Mist (<code>JUNIPER_MIST</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>LastPass Password Management (<code>LASTPASS</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Mongo Database (<code>MONGO_DB</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netapp Storagegrid (<code>NETAPP_STORAGEGRID</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>NGFW Enterprise (<code>GCP_NGFW_ENTERPRISE</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Office 365 Message Trace (<code>OFFICE_365_MESSAGETRACE</code>)</li>
<li>Okta Scaleft (<code>OKTA_SCALEFT</code>)</li>
<li>Oracle (<code>ORACLE_DB</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Orca Cloud Security Platform (<code>ORCA</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Red Hat Directory Server LDAP (<code>REDHAT_DIRECTORY_SERVER</code>)</li>
<li>Red Hat OpenShift (<code>REDHAT_OPENSHIFT</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sangfor Next Generation Firewall (<code>SANGFOR_NGAF</code>)</li>
<li>Security Command Center Error (<code>GCP_SECURITYCENTER_ERROR</code>)</li>
<li>Security Command Center Misconfiguration (<code>GCP_SECURITYCENTER_MISCONFIGURATION</code>)</li>
<li>Security Command Center Observation (<code>GCP_SECURITYCENTER_OBSERVATION</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>Security Command Center Unspecified (<code>GCP_SECURITYCENTER_UNSPECIFIED</code>)</li>
<li>Security Command Center Vulnerability (<code>GCP_SECURITYCENTER_VULNERABILITY</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>Sourcefire (<code>SOURCEFIRE_IDS</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Symantec Endpoint Protection (<code>SEP</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Trend Micro Deep Security (<code>TRENDMICRO_DEEP_SECURITY</code>)</li>
<li>Trend Micro Vision One Observerd Attack Techniques (<code>TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES</code>)</li>
<li>Ubiquiti UniFi Switch (<code>UBIQUITI_SWITCH</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Upwind (<code>UPWIND</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>VMWare VSphere (<code>VMWARE_VSPHERE</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Wiz.io (<code>WIZ_IO</code>)</li>
<li>Workday User Activity (<code>WORKDAY_USER_ACTIVITY</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zscaler (<code>ZSCALER_WEBPROXY</code>)</li>
<li>Zscaler CASB (<code>ZSCALER_CASB</code>)</li>
<li>Zscaler DLP (<code>ZSCALER_DLP</code>)</li>
<li>Zscaler Private Access (<code>ZSCALER_ZPA</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Azure Software Vulnerabilities (<code>AZURE_SOFTWARE_VULNERABILITIES</code>)</li>
<li>Caller Verify (<code>CALLER_VERIFY</code>)</li>
<li>CertSecure Log (<code>CERTSECURE_LOG</code>)</li>
<li>Cisco MultiCloud Defense Firewall (<code>CISCO_MULTICLOUD_DEFENSE_FIREWALL</code>)</li>
<li>Cursor (<code>CURSOR</code>)</li>
<li>Cyfirma (<code>CYFIRMA_DECYFIR_LOG</code>)</li>
<li>Databahn (<code>DATABAHN</code>)</li>
<li>Flare Darkweb Alerts (<code>FLARE_DARKWEB_ALERTS</code>)</li>
<li>Fortinet FortiAppSec Cloud (<code>FORTINET_FORTIAPPSEC</code>)</li>
<li>Hikvision Network Video Recorders (<code>HIKVISION_NVR</code>)</li>
<li>IBM B2B Integrator (<code>IBM_B2B_INTEGRATOR</code>)</li>
<li>IBM InfoSphere Virtual Data Pipeline (<code>IBM_VDP</code>)</li>
<li>Imperva Account TakeOver (<code>IMPERVA_ATO</code>)</li>
<li>Imperva Client Side Protection (<code>IMPERVA_CSP</code>)</li>
<li>Imperva DNS (<code>IMPERVA_DNS</code>)</li>
<li>Imperva Network Security (<code>IMPERVA_NETWORK_SECURITY</code>)</li>
<li>Microsoft Defender XDR (<code>MICROSOFT_DEFENDER_XDR</code>)</li>
<li>Nakivo Backup and Recovery (<code>NAKIVO_BACKUP</code>)</li>
<li>Netcraft Takedown (<code>NETCRAFT_TAKEDOWN</code>)</li>
<li>Next Level Performance Amplify (<code>NXL_AMPLIFY</code>)</li>
<li>Siemens Desigo (<code>SIEMENS_DESIGO</code>)</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>1Password Audit Events (<code>ONEPASSWORD_AUDIT_EVENTS</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS CloudFront (<code>AWS_CLOUDFRONT</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure AD Sign-In (<code>AZURE_AD_SIGNIN</code>)</li>
<li>Azure SQL (<code>AZURE_SQL</code>)</li>
<li>Azure Storage Audit (<code>AZURE_STORAGE_AUDIT</code>)</li>
<li>Barracuda WAF (<code>BARRACUDA_WAF</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>Cisco ACS (<code>CISCO_ACS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>Corelight (<code>CORELIGHT</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>Duo Administrator Logs (<code>DUO_ADMIN</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>Elastic Audit Beats (<code>ELASTIC_AUDITBEAT</code>)</li>
<li>Elastic Windows Event Log Beats (<code>ELASTIC_WINLOGBEAT</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Asset Inventory (<code>GCP_CLOUD_ASSET_INVENTORY</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Compute Context (<code>GCP_COMPUTE_CONTEXT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>GTB Technologies DLP (<code>GTB_DLP</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva (<code>IMPERVA_WAF</code>)</li>
<li>Imperva CEF (<code>IMPERVA_CEF</code>)</li>
<li>Imperva DRA (<code>IMPERVA_DRA</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Island Browser logs (<code>ISLAND_BROWSER</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Juniper Mist (<code>JUNIPER_MIST</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>LastPass Password Management (<code>LASTPASS</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Mongo Database (<code>MONGO_DB</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netapp Storagegrid (<code>NETAPP_STORAGEGRID</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>NGFW Enterprise (<code>GCP_NGFW_ENTERPRISE</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Office 365 Message Trace (<code>OFFICE_365_MESSAGETRACE</code>)</li>
<li>Okta Scaleft (<code>OKTA_SCALEFT</code>)</li>
<li>Oracle (<code>ORACLE_DB</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Orca Cloud Security Platform (<code>ORCA</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Red Hat Directory Server LDAP (<code>REDHAT_DIRECTORY_SERVER</code>)</li>
<li>Red Hat OpenShift (<code>REDHAT_OPENSHIFT</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sangfor Next Generation Firewall (<code>SANGFOR_NGAF</code>)</li>
<li>Security Command Center Error (<code>GCP_SECURITYCENTER_ERROR</code>)</li>
<li>Security Command Center Misconfiguration (<code>GCP_SECURITYCENTER_MISCONFIGURATION</code>)</li>
<li>Security Command Center Observation (<code>GCP_SECURITYCENTER_OBSERVATION</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>Security Command Center Unspecified (<code>GCP_SECURITYCENTER_UNSPECIFIED</code>)</li>
<li>Security Command Center Vulnerability (<code>GCP_SECURITYCENTER_VULNERABILITY</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>Sourcefire (<code>SOURCEFIRE_IDS</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Symantec Endpoint Protection (<code>SEP</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Trend Micro Deep Security (<code>TRENDMICRO_DEEP_SECURITY</code>)</li>
<li>Trend Micro Vision One Observerd Attack Techniques (<code>TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES</code>)</li>
<li>Ubiquiti UniFi Switch (<code>UBIQUITI_SWITCH</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Upwind (<code>UPWIND</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>VMWare VSphere (<code>VMWARE_VSPHERE</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Wiz.io (<code>WIZ_IO</code>)</li>
<li>Workday User Activity (<code>WORKDAY_USER_ACTIVITY</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zscaler (<code>ZSCALER_WEBPROXY</code>)</li>
<li>Zscaler CASB (<code>ZSCALER_CASB</code>)</li>
<li>Zscaler DLP (<code>ZSCALER_DLP</code>)</li>
<li>Zscaler Private Access (<code>ZSCALER_ZPA</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Azure Software Vulnerabilities (<code>AZURE_SOFTWARE_VULNERABILITIES</code>)</li>
<li>Caller Verify (<code>CALLER_VERIFY</code>)</li>
<li>CertSecure Log (<code>CERTSECURE_LOG</code>)</li>
<li>Cisco MultiCloud Defense Firewall (<code>CISCO_MULTICLOUD_DEFENSE_FIREWALL</code>)</li>
<li>Cursor (<code>CURSOR</code>)</li>
<li>Cyfirma (<code>CYFIRMA_DECYFIR_LOG</code>)</li>
<li>Databahn (<code>DATABAHN</code>)</li>
<li>Flare Darkweb Alerts (<code>FLARE_DARKWEB_ALERTS</code>)</li>
<li>Fortinet FortiAppSec Cloud (<code>FORTINET_FORTIAPPSEC</code>)</li>
<li>Hikvision Network Video Recorders (<code>HIKVISION_NVR</code>)</li>
<li>IBM B2B Integrator (<code>IBM_B2B_INTEGRATOR</code>)</li>
<li>IBM InfoSphere Virtual Data Pipeline (<code>IBM_VDP</code>)</li>
<li>Imperva Account TakeOver (<code>IMPERVA_ATO</code>)</li>
<li>Imperva Client Side Protection (<code>IMPERVA_CSP</code>)</li>
<li>Imperva DNS (<code>IMPERVA_DNS</code>)</li>
<li>Imperva Network Security (<code>IMPERVA_NETWORK_SECURITY</code>)</li>
<li>Microsoft Defender XDR (<code>MICROSOFT_DEFENDER_XDR</code>)</li>
<li>Nakivo Backup and Recovery (<code>NAKIVO_BACKUP</code>)</li>
<li>Netcraft Takedown (<code>NETCRAFT_TAKEDOWN</code>)</li>
<li>Next Level Performance Amplify (<code>NXL_AMPLIFY</code>)</li>
<li>Siemens Desigo (<code>SIEMENS_DESIGO</code>)</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.87 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 30, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_30_2026</id>
    <updated>2026-05-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_30_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1154">v1.15.4</h3>
<p>On May 30, 2026 we released an updated version of the Apigee hybrid software, v1.15.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_24_2026">Release 6.3.86</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 29, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_29_2026</id>
    <updated>2026-05-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_29_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On May 29, 2026, we released an updated version of the Apigee UI.</p>
<h3>Feature</h3>
<p><b>Apigee EventFlow now supports the DataCapture policy</b></p>
<p>You can now use the DataCapture policy within an EventFlow to extract and
persist data from server-sent events (SSE) streams, such as token counts and
other fields from streaming LLM responses.
For more information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-platform/develop/server-sent-events#datacapture-token-counts">Use the DataCapture policy to capture token counts</a>.</p>
<h3>Feature</h3>
<p><b>Manage Spaces in the Apigee UI</b></p>
<p>You can now create, view, update, and delete spaces, and manage their Identity and Access Management (IAM) policies directly in the Apigee UI.
Previously, these actions could only be performed using the Apigee API.
For more information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/spaces/apigee-spaces-overview">Apigee Spaces overview</a>.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images">preconfigured base images</a>
include <a href="https://antigravity.google/product/antigravity-cli">Antigravity CLI</a>.</p>
<h3>Announcement</h3>
<p>The base VM was upgraded to use <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/features-and-benefits">Container-Optimized OS</a>
<a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129">129 LTS</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images#list_of_preconfigured_base_images">JetBrains RubyMine preconfigured base image</a>
uses a custom gem directory (<code>/usr/local/share/gems/ruby/3.1.0</code>).</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_3">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Issue</h3>
<p>In GKE version 1.35 and later, workloads that use Workload Identity to
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/workload-identity">authenticate to Google Cloud
APIs</a> might experience
transient connectivity timeouts or refused connections to the GKE metadata
server immediately following node startup. For recommendations and workarounds,
see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/troubleshooting/authentication#troubleshoot-timeout">Timeout errors at Pod
startup</a>.</p>
<h3>Feature</h3>
<p>GKE Gateway now supports backend authenticated TLS for Gateway-originated
connections to Pods or InferencePools for the following GatewayClasses:</p>
<ul>
<li><code>gke-l7-global-external-managed</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-rilb</code></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>The Data Lineage API includes the <a href="dataplex/docs/reference/data-lineage/rest/v1/projects.locations/searchLineageStreaming?rep_location=global"><code>searchLineageStreaming</code></a> method that performs a breadth-first search (upstream or downstream) to retrieve lineage links for an asset identified by its Fully Qualified Name (FQN).</p>
<p>For more information, see the Data Lineage API reference for
<a href="https://docs.cloud.google.com/dataplex/docs/reference/data-lineage/rest">REST</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine):
Added support for selecting specific <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/configuring-clusters/confidential-compute">Confidential Computing</a> technologies (AMD SEV, AMD SEV-SNP, Intel TDX) when creating clusters using the new <code>--confidential-compute-type</code> flag in <code>gcloud</code> and the <code>confidentialInstanceType</code> field in the API. The boolean <code>--enable-confidential-compute</code> flag is now deprecated but will continue to function, defaulting to AMD SEV for backward compatibility.</p>
<ul>
<li>Introduced <code>confidentialInstanceType</code> enum in the <a href="https://docs.cloud.google.com/managed-spark/docs/reference/rest/v1/ClusterConfig#confidentialinstanceconfig">API</a>.</li>
<li>The <code>--enable-confidential-compute</code> flag and <code>enableConfidentialCompute</code> field are deprecated in favor of the new type-specific flag/field.</li>
<li>Clusters created with the deprecated boolean flag will default to <code>SEV</code>.</li>
<li>Added validation for machine type compatibility for <code>SEV</code>, <code>SEV-SNP</code>, and <code>TDX</code>.</li>
<li>Updated live migration logic to support compatible machine types and CPU platforms for each technology, including N2D and C3D for SEV.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 28, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_28_2026</id>
    <updated>2026-05-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_28_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>You can now view the Google Cloud Backup and DR Service protection summary at
the organization and folder levels. To learn more about protection summary, see
<a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/backup-admin/protection-summary">Find unprotected resources using protection summary</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>As part of Bigtable Enterprise Plus <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">edition</a>,
you can configure a retention period of up to 365 days for backups. This feature
is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/backups">Bigtable backups overview</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Cloud Logging API on the REST reference pages. For an example, see
<a href="https://docs.cloud.google.com/logging/docs/reference/v2/rest/v2/projects.locations.buckets/list?rep_location=global">Method: projects.locations.buckets.list</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Breaking</h3>
<p>As of August 26, 2026, in buckets with hierarchical namespace enabled,
the <a href="https://docs.cloud.google.com/storage/docs/lifecycle">Object Lifecycle Management</a> <code>Delete</code> action will
delete empty folders when the empty folder meets all of the conditions in the
lifecycle rule.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Observability API and for the Telemetry API on their REST reference pages.
For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/reference/api-overview">API overview</a>.</p>
<h2 class="release-note-product-title">Error Reporting</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Error Reporting API on the REST reference pages. For an example, see
<a href="https://docs.cloud.google.com/error-reporting/reference/rest/v1beta1/projects.events/list?rep_location=global">Method: projects.events.list</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Release of Core Assistant (General Availability) and new Trace and Metrics information for Core Assistant (Preview)</strong></p>
<p>This release includes Core Assistant, a Google-provided ("Made by Google") root
agent that handles interactions when users talk to the Gemini Enterprise app
without specifying any other agent.</p>
<p>Core Assistant is
<a href="https://cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<p>Core Assistant includes new observability and monitoring functionality:</p>
<ul>
<li><strong>Traces</strong>: A chronological summary and visualization of trace spans showing execution flow, duration, inputs, outputs, and precise details if OpenTelemetry trace and logging instrumentation is enabled.</li>
<li><strong>Metrics</strong>: A default-on dashboard displaying session counts, latency, agent invocations, tool call counts, and error rates without any extra billing costs.</li>
</ul>
<p>The Trace and Metrics tabs are in
<a href="https://cloud.google.com/products#product-launch-stages">Public Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/core-assistant">Observe and trace agent behavior with Core Assistant</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Agent Platform Gemini 3.1 Flash Image and Gemini 3 Pro Image</strong></p>
<p>Gemini Enterprise Agent Platform Gemini 3.1 Flash Image and Gemini 3 Pro Image
are <a href="https://cloud.google.com/products#product-launch-stages">Generally
Available</a>.</p>
<p>With this release, Gemini 3.1 Flash Image and Gemini 3 Pro Image support 4K
image outputs in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>Also supported in this release, Gemini 3.1 Flash Image supports video inputs in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. You can use
video inputs to generate thumbnails or representative images of videos.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-image">Gemini 3.1 Flash Image (Nano Banana
2)</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-pro-image">Gemini 3 Pro Image (Nano Banana
Pro)</a></li>
</ul>
<h3>Deprecated</h3>
<p><strong>Agent Platform Gemini 3.1 Flash Image Preview and Gemini 3 Pro Image Preview deprecation</strong></p>
<p>Gemini Enterprise Agent Platform Gemini 3.1 Flash Image Preview and Gemini 3 Pro
Image Preview are deprecated. We recommend that you update your model endpoints
before July 17, 2026, to avoid service disruption.</p>
<p>The following are the discontinued endpoints and recommended endpoint migration:</p>
<table>
<thead>
<tr>
<th>Discontinued endpoints</th>
<th>Recommended endpoint migration</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>gemini-3.1-flash-image-preview</code></td>
<td><code>gemini-3.1-flash-image</code></td>
</tr>
<tr>
<td><code>gemini-3-pro-image-preview</code></td>
<td><code>gemini-3-pro-image</code></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Opus 4.8</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/opus-4-8">Claude Opus 4.8</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>C4A bare metal instances are generally available with GKE clusters. For more
information, see the <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/arm-on-gke">Arm workloads on
GKE</a>
document, including the "Requirements and limitations" section for specific
version requirements.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/confidential-gke-nodes#confidential-gke-nodes">Confidential GKE
Nodes</a>
now support cluster level enablement of <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview#amd_sev-snp">AMD
SEV-SNP</a>
and <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview#intel_tdx">Intel
TDX</a>
on GKE Autopilot.</p>
<h3>Feature</h3>
<p>In GKE versions 1.36.0-gke.2459000 and later, you can directly configure Cloud
Logging for L4 load balancer backend services by using the L4LBConfig
CustomResourceDefinition (CRD).</p>
<p>This feature is available for the following load balancer types:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/internal-load-balancing#enable-logging">Internal L4 load
balancers</a>
with subsetting enabled.</li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/backend-service-based-external-load-balancer#enable-logging">External L4 load
balancers</a>
with regional backend services (RBS) enabled.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Unified and Upgraded Chronicle API</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> has been unified with API resources from <a href="https://docs.cloud.google.com/chronicle/docs/soar/reference/working-with-chronicle-soar-apis">legacy SOAR API</a>. Further, we've upgraded the following Chronicle API resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>The following features and resources are included in this update:</p>
<table>
<tr>
<td style="background-color: null"><strong>Feature</strong>
</td>
<td style="background-color: null"><strong>Chronicle API Resources upgraded to v1</strong>
</td>
</tr>
<tr>
<td style="background-color: null">Alerts and ATIs, UEBA
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.threatCollections">Threat Collection</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.iocs">IoC</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.coverageDetails">CoverageDetail</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getRiskConfig">EntityRisk</a>
</td>
</tr>
<tr>
<td style="background-color: null">Dashboards
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.nativeDashboards">NativeDashboard</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardCharts">DashboardChart</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardQueries">DashboardQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentNativeDashboards">FeaturedContentNativeDashboard</a>
</td>
</tr>
<tr>
<td style="background-color: null">Data Tables
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables">DataTable</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables.dataTableRows">DataTableRow</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTableOperationErrors">DataTableOperationError</a>
</td>
</tr>
<tr>
<td style="background-color: null">Ingestion
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.logs">Logs</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feeds">Feed</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas.logTypeSchemas">LogTypeSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas">FeedSourceSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedPacks">FeedPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.forwarders">Forwarder</a>
</td>
</tr>
<tr>
<td style="background-color: null">Normalization
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes">Logtype</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.parsers">Parser</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ingestionLogLabels">IngestionLogLabel</a>
</td>
</tr>
<tr>
<td style="background-color: null">Detections
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.findingsRefinements">FindingsRefinement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/verifyRuleText">VerifyRuleText</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentRules">FeaturedContentRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ruleExecutionErrors">RuleExecutionError</a>
</td>
</tr>
<tr>
<td style="background-color: null">Search &amp; Investigation
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.events">Event</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entities">Entity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.users.searchQueries">SearchQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.savedColumnSets">SavedColumnSet</a>
</td>
</tr>
<tr>
<td style="background-color: null">Exports
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.bigQueryExport">BigQueryExportService</a>
</td>
</tr>
<tr>
<td style="background-color: null">Enrichment Controls
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.enrichmentControls">EnrichmentControl</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getEnrichmentCombination">EnrichmentCombination</a>
</td>
</tr>
<tr>
<td style="background-color: null">SOAR
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases">Case</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts">CaseAlert</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseStageDefinitions">CaseStageDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseTagDefinitions">CaseTagDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseQueueFilters">CaseQueueFilter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseCloseDefinitions">CaseCloseDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.contextProperties">ContextProperty</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.involvedEntities">InvolvedEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.tasks">Task</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseComments">CaseComment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseWallRecords">CaseWallRecord</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages">ChatMessage</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.views">View</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ontologyRecords.visualFamilies">VisualFamily</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages.attachments">ChatMessages.attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.contentPacks">ContentPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.socRoles">SocRole</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.emailTemplates">EmailTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dynamicParameters">DynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entitiesBlocklists">EntitiesBlocklist</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environments">Environment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environmentGroups">EnvironmentGroup</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations">Integration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions">Integrationaction</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.userNotifications">UserNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions.revisions">Integrationactionrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors">Connector</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances">ConnectorInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.remoteAgents">RemoteAgent</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances.logs">Connectorlog</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.revisions">Connectorrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.integrationInstances">IntegrationInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.uniqueEntities">UniqueEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs">Integrationsjob</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances">JobInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances.logs">JobInstances.log</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.revisions">Jobs.revision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers">Integrationmanager</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers.revisions">Integrationmanagerrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.alertGroupingRules">AlertGroupingRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.announcements">Announcement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.attachments">Attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.customLists">CustomList</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.formDynamicParameters">FormDynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.marketplaceIntegrations">MarketplaceIntegration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.moduleSettings">ModuleSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.slaDefinitions">SlaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getNotificationSettings">NotificationSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.propertySchemaDefinitions">PropertySchemaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.requestTemplates">RequestTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarDomains">SoarDomain</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarNetworks">SoarNetwork</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskLinks">WorkdeskLink</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.systemNotifications">SystemNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskContacts">WorkdeskContact</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskNotes">WorkdeskNote</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getLocalization">LegacySoarUsers.localization</a>.
   </td>
</tr>
</table>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Manage access to preview features</strong></p>
<p>Google Sec0ps tenant administrators can enable or disable access to public preview features. Previously, all public preview features needed to be enabled through official Support channels.</p>
<p>The new <strong>Public Preview Features</strong> page lists all the public preview features, the status of each feature (on or off)—along with (when available) the expected GA date and a link to a relevant user guide.</p>
<aside class="note"><strong>Note:</strong><span> In <a href="https://docs.cloud.google.com/chronicle/docs/onboard#set-up-assured-workloads-folder">compliance-controlled tenants</a> (for example, FedRAMP or HIPAA), using the <strong>Public Preview Features</strong> page to turn features on and off isn't available. In these tenants, you must contact Google Sec0ps support to get public preview features enabled.</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/secops/preview-features-manage">Manage access to preview features</a>.</p>
<aside class="note"><strong>Note:</strong><span> It might take one to six days before you see the changes reflected in your region.</span></aside>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Upgraded Chronicle API</strong></p>
<p>We've upgraded the following <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for all new integrations, for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>The following features and resources are included in this update:</p>
<ul>
<li><strong>Alerts and ATIs, UEBA:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.threatCollections">Threat Collection</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.iocs">IoC</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.coverageDetails">CoverageDetail</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getRiskConfig">EntityRisk</a></li>
<li><strong>Dashboards:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.nativeDashboards">NativeDashboard</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardCharts">DashboardChart</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardQueries">DashboardQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentNativeDashboards">FeaturedContentNativeDashboard</a></li>
<li><strong>Data Tables:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables">DataTable</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables.dataTableRows">DataTableRow</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTableOperationErrors">DataTableOperationError</a></li>
<li><strong>Ingestion:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.logs">Logs</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feeds">Feed</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas.logTypeSchemas">LogTypeSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas">FeedSourceSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedPacks">FeedPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.forwarders">Forwarder</a></li>
<li><strong>Normalization:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes">Logtype</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.parsers">Parser</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ingestionLogLabels">IngestionLogLabel</a></li>
<li><strong>Detections:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.findingsRefinements">FindingsRefinement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/verifyRuleText">VerifyRuleText</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentRules">FeaturedContentRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ruleExecutionErrors">RuleExecutionError</a></li>
<li><strong>Search &amp; Investigation:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.events">Event</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entities">Entity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.users.searchQueries">SearchQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.savedColumnSets">SavedColumnSet</a></li>
<li><strong>Exports:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.bigQueryExport">BigQueryExportService</a></li>
<li><strong>Enrichment Controls:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.enrichmentControls">EnrichmentControl</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getEnrichmentCombination">EnrichmentCombination</a></li>
</ul>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Feature</h3>
<p><strong>Unified and Upgraded Chronicle API</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> has been unified with API resources from <a href="https://docs.cloud.google.com/chronicle/docs/soar/reference/working-with-chronicle-soar-apis">legacy SOAR API</a>. This unification provides a more robust, secure, and extensible experience. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>This update includes the following resources: <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases">Case</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts">CaseAlert</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseStageDefinitions">CaseStageDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseTagDefinitions">CaseTagDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseQueueFilters">CaseQueueFilter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseCloseDefinitions">CaseCloseDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.contextProperties">ContextProperty</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.involvedEntities">InvolvedEntity</a>,  <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.tasks">Task</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseComments">CaseComment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseWallRecords">CaseWallRecord</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages">ChatMessage</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.views">View</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ontologyRecords.visualFamilies">VisualFamily</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages.attachments">ChatMessages.attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.contentPacks">ContentPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.socRoles">SocRole</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.emailTemplates">EmailTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dynamicParameters">DynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entitiesBlocklists">EntitiesBlocklist</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environments">Environment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environmentGroups">EnvironmentGroup</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations">Integration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions">Integrationaction</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.userNotifications">UserNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions.revisions">Integrationactionrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors">Connector</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances">ConnectorInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.remoteAgents">RemoteAgent</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances.logs">Connectorlog</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.revisions">Connectorrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.integrationInstances">IntegrationInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.uniqueEntities">UniqueEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs">Integrationsjob</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances">JobInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances.logs">JobInstances.log</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.revisions">Jobs.revision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers">Integrationmanager</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers.revisions">Integrationmanagerrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.alertGroupingRules">AlertGroupingRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.announcements">Announcement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.attachments">Attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.customLists">CustomList</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.formDynamicParameters">FormDynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.marketplaceIntegrations">MarketplaceIntegration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.moduleSettings">ModuleSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.slaDefinitions">SlaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getNotificationSettings">NotificationSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.propertySchemaDefinitions">PropertySchemaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.requestTemplates">RequestTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarDomains">SoarDomain</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarNetworks">SoarNetwork</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskLinks">WorkdeskLink</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.systemNotifications">SystemNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskContacts">WorkdeskContact</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskNotes">WorkdeskNote</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getLocalization">LegacySoarUsers.localization</a>.</p>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h2 class="release-note-product-title">Secure Source Manager</h2>
<h3>Breaking</h3>
<p>To enhance security and address potential vulnerabilities (such as GHSA-3m6q-h5gj-7mrw), the Secure Source Manager Git-over-SSH server configuration has removed support for several legacy and insecure SSH algorithms.</p>
<p>SSH clients must support one or more of the following modern algorithms to connect:</p>
<ul>
<li><strong>Key Exchange Algorithms:</strong> <code>curve25519-sha256</code>, <code>diffie-hellman-group14-sha256</code></li>
<li><strong>Ciphers:</strong> <code>chacha20-poly1305@openssh.com</code>, <code>aes128-ctr</code>, <code>aes192-ctr,aes256-ctr</code>, <code>aes128-gcm@openssh.com</code>, <code>aes256-gcm@openssh.com</code></li>
<li><strong>MACs:</strong> <code>hmac-sha2-256-etm@openssh.com</code>, <code>hmac-sha2-256</code></li>
</ul>
<p>Users with old or non-standard SSH clients lacking support for these algorithms will be unable to connect using SSH for Git operations. Ensure your SSH client is up-to-date.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/attack-exposure-supported-features">Risk Engine</a> detects
toxic combinations that are related to Managed Service for Apache Spark (formerly known as Dataproc), including Lightning Engine.</p>
<h3>Feature</h3>
<p>Risk reports are updated to include more content in the <strong>Risk Engine introduction</strong>
and the <strong>System attack exposure</strong> pages. For more information about what's
included in risk reports, see <a href="https://docs.cloud.google.com/security-command-center/docs/risk-reports-overview">Risk reports overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 27, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_27_2026</id>
    <updated>2026-05-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_27_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=go#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/java-gen2/config/appref-xml#app_engine_apis"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=php#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=python#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>An updated version of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_odbc_driver">Simba ODBC driver for BigQuery</a>
is now available.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Two C4A bare metal machine types are generally
available:</p>
<ul>
<li><code>c4a-standard-96-metal</code> with 96 vCPUs and 384 GB of DDR5
memory</li>
<li><code>c4a-highmem-96-metal</code> with 96 vCPUs and 768 GB DDR5
memory</li>
</ul>
<p>These two machine types support Hyperdisk Balanced, Hyperdisk Extreme, Hyperdisk Throughput, and Hyperdisk ML
volume storage and up to 100 Gbps of network bandwidth.</p>
<p>To learn more about the C4A machine family, read
<a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#n4a_series">General-purpose machines</a>.
To see where you can create C4A bare metal instances, read
<a href="https://docs.cloud.google.com/compute/docs/instances/bare-metal-instances">Bare metal instances</a>.</p>
<h2 class="release-note-product-title">Document AI</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/document-ai/docs/layout-parse-chunk">Layout parser</a> image and
table annotations is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability (GA)</a>.</p>
<p>Layout parser can identify if there are images or tables in parsed documents.
When found, images and tables are annotated as a descriptive block of text with
the information depicted in the image and table.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Slack data store</strong></p>
<p>The Slack data store is generally available (GA) in Gemini Enterprise.</p>
<p>You can connect a Slack Workspace to search and read conversations,
files, and messages using natural language. You can also perform actions,
such as sending and scheduling messages, directly from the
Gemini Enterprise app chat box.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/slack">Connect Slack</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>User ID logging now included with agent logs when you opt in to "Enable logging of prompt inputs and response outputs"</strong></p>
<p>Prompt input and response output logging now includes the
<code>user.id</code> field. This addition allows better tracking of
anomalous tool interactions.</p>
<aside class="special"><strong>Important:</strong><span> Logging of <code>user.id</code> is included when opting in to "Enable logging of
prompt inputs and response outputs" effective May 22, 2026 and later and with
the Agent Development Kit (ADK) version 2.1 and later. If you opted in prior to
this change, your logs do not include <code>user.id</code>. You will need to redeploy your
agents and opt-in again for this setting to take effect.</span></aside>
<p>For details on configuration, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/tracing#write-traces">Write traces for an agent</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advanced reporting dashboards 4.22</strong></p>
<p>We've released version 4.22 of the advanced reporting dashboards.</p>
<h3>Feature</h3>
<p><strong>Added a Location filter to dashboards</strong></p>
<p>The following dashboards now include a <strong>Location</strong> filter:</p>
<ul>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-real-time-channel-perf">Real-time Channel
Performance</a></p></li>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-transfers">Transfers</a></p></li>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-interval">Queue
Interval</a></p></li>
</ul>
<h3>Feature</h3>
<p><strong>Queue Performance dashboard improvements</strong></p>
<p>We've made the following improvements to the <strong>Queue Performance - Calls</strong> and
<strong>Queue Performance - Chats</strong> dashboards:</p>
<ul>
<li><p>Added the dashboards to the Advanced Reporting Landing Page.</p></li>
<li><p>Added a <strong>Support Phone Number</strong> filter.</p></li>
<li><p>Renamed the <strong>Total Inbound Handled</strong> tile (calls only) to <strong>Total Queue
Answered</strong>.</p></li>
<li><p>Added a <strong>Total Failed</strong> tile.</p></li>
<li><p>In the <strong>Queue Summary</strong> table, removed the <strong>Total Inbound Calls Handled</strong>
column and added the following columns: <strong>Total Queue Interactions</strong>,
<strong>Total Queue Entries</strong>, <strong>Total Queue Answered</strong>, <strong>Total Failed</strong>, and
<strong>Total Transfers</strong>.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-performance">Queue Performance
dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>General dashboard updates</strong></p>
<ul>
<li><p>In the <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-perf-overview">Performance
Overview</a>
dashboard, we renamed the following tiles:</p>
<ul>
<li><p><strong>Queued Now</strong> to <strong>Current Queued Now</strong></p></li>
<li><p><strong>Max Queue Time</strong> to <strong>Current Max Queue Time</strong></p></li>
</ul></li>
<li><p>The <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-calls-connected">Real-time Connected -
Calls</a> and
<a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-chats-connected">Real-time Connected -
Chats</a>
dashboards now include the following tiles:</p>
<ul>
<li><p><strong>Total Connected Calls</strong> (calls only)</p></li>
<li><p><strong>Total Connected Chats</strong> (chats only)</p></li>
<li><p><strong>Avg Current Sentiment Score</strong></p></li>
</ul></li>
<li><p>In the <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-group-perf">Queue Group Performance -
All</a>
dashboard, we renamed the <strong>Lang</strong> filter to <strong>Language</strong>.</p></li>
</ul>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where the CSAT scores in the <strong>Performance Overview</strong> and
<strong>CSAT</strong> dashboards didn't match.</p></li>
<li><p>Fixed an issue where the <strong>Queue Performance</strong> dashboard incorrectly totaled
queue interactions, resulting in lower counts than expected.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Virtual Agents Chats</strong> table displayed the wrong chat.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Failed Interaction</strong> column of the <strong>Chat Metric Detail</strong> table displayed
<code>False</code> for a failed interaction.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Failed Interaction</strong> column of the <strong>Chat Metric Detail</strong> table displayed
<code>False</code> for a failed interaction.</p></li>
<li><p>Fixed an issue where the <strong>Chat ID</strong> filter on the <strong>Queue Performance -
Chats</strong> dashboard incorrectly displayed placeholder values.</p></li>
<li><p>Fixed an issue where scheduled exports of large queries were limited to 500
rows, causing reporting delays.</p></li>
<li><p>Fixed an issue in the <strong>Historical Data</strong> table of the <strong>Agent Activity</strong>
dashboard where the <strong>Start Time</strong> and <strong>End Time</strong> columns indicated
incorrect durations for agents belonging to multiple teams.</p></li>
<li><p>Fixed an issue where short abandoned calls and chats were incorrectly
included in the <strong>Abandons</strong> dashboard, causing inaccurate reporting of
queue abandon times.</p></li>
<li><p>Fixed an issue where dashboard windows didn't fully display their contents.</p></li>
</ul>
<h2 class="release-note-product-title">Google Cloud Marketplace Partners</h2>
<h3>Change</h3>
<p>We've reduced the processing and delivery delay for Google Cloud Marketplace
partner reports from 2 days (D+2) to 1 day (D+1), accelerating by one day the
delivery of the
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-customer-insight">Customer Insights reports</a>
to Cloud Marketplace partners.</p>
<p>For information about processing times, see
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-customer-insight#report_frequency">Customer Insights report frequency</a></p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.34.500-gke.108 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.34.500-gke.108 runs on Kubernetes v1.34.7-gke.200.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.500-gke.108:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where, when setting <code>stackdriver.disableVsphereResourceMetrics</code> to true in the cluster configuration file, user cluster installations or upgrades stalled indefinitely because the installer erroneously deleted the vsphere-ca-certificate ConfigMap, causing vsphere-csi-controller pods to fail with mount errors. You no longer need to manually recreate the ConfigMap or scale down the vsphere-metrics-exporter deployment as a workaround. </li>
<li>Fixed an issue where, when recreating a user cluster with a previously used name (which commonly occurs during Terraform deployments or manual reinstalls), cluster provisioning stalled indefinitely in the provisioning state due to a missing k8s-health-check service account. The installer ensures that the service account is created, eliminating the need to manually create the service account as a workaround. </li>
<li>Fixed an issue where the <code>gkectl diagnose</code> command failed to run on standard user clusters managed by an advanced admin cluster.</li></ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.34.500-gke.108 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.34.500-gke.108 runs on Kubernetes v1.34.7-gke.200.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.500-gke.108:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where, if a new control plane node failed to join a cluster
during bootstrapping or scaling (associated with installer Ansible runner job
failures), orphaned etcd memberships were not cleaned up, causing the existing
control plane's API server to restart repeatedly (flap) and blocking subsequent
retry attempts.
</li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane node
while waiting for the local API server to restart, causing nodes to temporarily
report an Unknown status and triggering transient routing disruptions (such as
503 Service Unavailable or ImagePullBackOff errors) for workloads scheduled on
those nodes.
</li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, when recreating a user cluster with a previously used
name (which commonly occurs during Terraform deployments or manual
reinstalls), cluster provisioning stalled indefinitely in the provisioning
state due to a missing k8s-health-check service account. The installer
ensures that the service account is created, eliminating the need to manually
create the service account as a workaround.</li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1055000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.1993000</li>
<li>1.35.3-gke.2190000</li>
<li>1.36.0-gke.1575000</li>
<li>1.36.0-gke.1759000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2530000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1942000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1318000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1551000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r21-security-updates">(2026-R21) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2558000</td>
<td>cos-117-18613-613-5</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-5_">cos-117-18613-613-5 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.1967000</td>
<td>cos-117-18613-613-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-7_">cos-117-18613-613-7 release notes</a></td>
</tr>
<tr>
<td>1.33.12-gke.1059000</td>
<td>cos-121-18867-381-125</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-125_">cos-121-18867-381-125 release notes</a></td>
</tr>
<tr>
<td>1.35.5-gke.1057000</td>
<td>cos-125-19216-395-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-7_">cos-125-19216-395-7 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2459000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1055000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.1993000</li>
<li>1.35.3-gke.2190000</li>
<li>1.36.0-gke.1575000</li>
<li>1.36.0-gke.1759000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2530000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1942000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1318000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1551000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Standard parser support policy</strong></p>
<p>Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The new policy structures service level objectives (SLOs) and request triaging by customer support tiers (Standard versus Expert/Expert+), and prioritizes core security data through <a href="https://docs.cloud.google.com/chronicle/docs/reference/important-udm-fields">Important UDM Fields</a>. Additionally, the policy outlines a community-driven model where low-usage, longtail prebuilt parsers migrate to a dedicated GitHub repository maintained by partners and the Google SecOps community. </p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/standard-parser-support-policy">Standard parser support policy</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p>New <strong>Cloud Identity</strong> integration</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Standard parser support policy</strong></p>
<p>Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The new policy structures service level objectives (SLOs) and request triaging by customer support tiers (Standard versus Expert/Expert+), and prioritizes core security data through <a href="https://docs.cloud.google.com/chronicle/docs/reference/important-udm-fields">Important UDM Fields</a>. Additionally, the policy outlines a community-driven model where low-usage, longtail prebuilt parsers migrate to a dedicated GitHub repository maintained by partners and the Google SecOps community. </p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/standard-parser-support-policy">Standard parser support policy</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>You can use the data lineage remote MCP server to interact with Knowledge Catalog (formerly Dataplex Universal Catalog) to query data lineage graphs, discover upstream data provenance, and analyze downstream impact.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.
For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/use-lineage-mcp">Use the data lineage remote MCP server</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>The following features will begin rolling out as part of Looker 26.8.</p>
<h3>Feature</h3>
<p>The Looker <a href="https://docs.cloud.google.com/looker/docs/continuous-integration">Continuous Integration (CI)</a> feature is now generally available.</p>
<h3>Feature</h3>
<p>Conversational Analytics now supports the ability to run queries when users are in <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#development_mode">Development Mode</a>.</p>
<h3>Feature</h3>
<p>Now available in preview for BigQuery and Snowflake connections, Looker integrates with in-database analytic models (<a href="https://docs.cloud.google.com/bigquery/docs/graph-overview">BigQuery Graph</a> and <a href="https://docs.snowflake.com/en/user-guide/views-semantic/overview">Snowflake semantic views</a>), so that you can keep your semantic definitions consistent across Looker and other BI tools, applications, or workloads that interface with your data warehouse.</p>
<p>See the <a href="https://docs.cloud.google.com/looker/docs/analytic-models">In-database analytic models</a> documentation page for more information.</p>
<p><strong>Note:</strong> This item was added on May 28, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, dashboard editors can change the size and layout of dashboard tiles with more granularity. To enable this feature, a Looker admin must turn on the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-labs#granular-dashboard-sizing"><strong>Granular Dashboard Sizing</strong></a> setting on the <strong>Preview</strong> page in the <strong>Admin</strong> panel.</p>
<h3>Feature</h3>
<p>Now available in preview, enhanced observability metrics, including engagement and token usage data, are available for Conversational Analytics on the <a href="https://docs.cloud.google.com/looker/docs/system-activity-dashboards#conversational-analytics">Conversational Analytics System Activity dashboard</a>. To use this feature, a Looker admin must turn on the <strong>Conversational Analytics Observability</strong> setting on the <strong>Preview</strong> admin page. <strong>Note:</strong> Token usage monitoring for Conversational Analytics is not available at this time. This item was updated on June 1, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, you can use natural language to instruct a Conversational Analytics data agent to create a <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-agentic-workflows">workflow</a> that notifies you when your data has met certain conditions. To use this feature, a Looker admin must turn on the <strong>Agentic Workflows</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/mcp">Looker-managed Model Context Protocol (MCP) server</a> allows AI agents to securely connect to your Looker instance without requiring separate middleware. Looker admins can enable this feature and <a href="https://docs.cloud.google.com/looker/docs/admin-panel-platform-mcp#model_context_protocol_mcp_settings">manage which AI tools</a> are available to developers from the new <strong>Model Context Protocol (MCP)</strong> page in the <strong>Admin</strong> panel. Usage of the managed MCP server is also tracked within <a href="https://docs.cloud.google.com/looker/docs/mcp#system_activity">System Activity Explores</a> and <a href="https://docs.cloud.google.com/looker/docs/looker-core-audit-logging#sample_queries">Cloud Audit Logs</a>.</p>
<h3>Feature</h3>
<p>Model localization for imported projects will be supported in a future release.</p>
<p><strong>Note:</strong> This item was updated on May 28, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, you can <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents">publish the Conversational Analytics data agents</a> that you create in Looker to Gemini Enterprise. All users who have the <code>save_agents</code> permission will be granted the <code>publish_agent_externally</code> permission. To use this feature, a Looker admin must turn on the <strong>Publish to Gemini Enterprise</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Now available in preview, you can create and use Conversational Analytics <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards">data agents on Looker user-defined dashboards</a>. Conversational Analytics uses the <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#production_mode">Production Mode</a> of content when it queries Looker dashboards. To use this feature, a Looker admin must turn on the <strong>Enable Dashboard Agents</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Looker has introduced the following new feature updates for tabbed dashboards:</p>
<ul>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#add-buttons-with-navigation-to-tabs">add buttons with navigation to tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#duplicate-tabs">duplicate tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#apply-filters">select all or deselect all tiles on a dashboard tab for filters</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#monitor-dashboard-tab-usage-with-system-activity">monitor dashboard tab usage with the <strong>Dashboard</strong> System Activity Explore</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#schedule-pdf">schedule or send a single dashboard tab or a specific set of tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#download-pdf">download a single dashboard tab or a specific set of tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#add-to-board">add a dashboard tab view to a board</a></li>
</ul>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service"><strong>Self-service Explores</strong></a> feature is now supported on Snowflake connections. Your Looker admin can select a Snowflake connection in the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore#enable"><strong>Default Connection</strong> field</a> of the <strong>Self-service Explores</strong> admin page. On Snowflake connections, you can <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service#files-from-computer">upload comma-separated files (CSV) and Excel files (XLS and XLSX)</a> to create a self-service Explore.</p>
<h3>Feature</h3>
<p>Looker has introduced a security sandboxing enhancement for Git command-line interface (CLI) operations. For Looker projects that are configured with SSH connections, this enhancement restricts which directories and executables can be accessed on the instance when Git worktree commands are executed. Looker projects that use HTTPS connections are not affected.</p>
<p>This sandboxing feature is enabled automatically for Cloud-hosted Looker (original) and Looker (Google Cloud core) instances starting in Looker 26.8.</p>
<p>For <a href="https://docs.cloud.google.com/looker/docs/glossary#customer-hosted">customer-hosted</a> Looker instances, this security enhancement is available starting in Looker 26.10. To opt in to security sandboxing, you must install the <a href="https://proot-me.github.io/"><code>proot</code> package</a> on your Looker host machine. If <code>proot</code> isn't installed, SSH-connected Git operations will still be executed successfully but won't have the sandboxing protection.</p>
<p><strong>Note:</strong> This item was updated on May 29, 2026.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles">Admin &gt; Roles panel</a> user interface has been updated.</p>
<h3>Feature</h3>
<p>Looker admins can no longer create or manage API credentials for individual standard users in Looker (original) instances. Users must now <a href="https://docs.cloud.google.com/looker/docs/user-account#api-keys">manage their own keys</a> from their <strong>Account</strong> page. Admins can <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-users#api_keys">enable or disable self-service API key management</a> for users and continue to manage credentials for API-only service accounts. To improve security, API keys are no longer visible to admins while they are <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-users#impersonating_users">sudoing</a> as another user.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p>Managed Service for Apache Airflow now
<a href="https://docs.cloud.google.com/composer/docs/composer-3/create-and-manage-tags">supports Google Cloud tags</a>
for environments.</p>
<p><a href="https://docs.cloud.google.com/resource-manager/docs/tags/tags-overview">Tags</a>
provide a way to create annotations for resources, and conditionally allow or
deny policies based on whether a resource has a specific tag.</p>
<h3>Feature</h3>
<p>In Managed Airflow (Gen 3), it is now possible to
create Kubernetes Secrets with the <code>kubernetes.io/dockerconfigjson</code>
<a href="https://kubernetes.io/docs/concepts/configuration/secret/#secret-types">secret type</a>
through the beta Cloud Composer API, in addition to the default
<code>Opaque</code> secret type. For more information, see <a href="https://docs.cloud.google.com/composer/docs/composer-3/use-kubernetes-pod-operator#api">Manage Kubernetes Secrets</a>.</p>
<h3>Fixed</h3>
<p>(Airflow 3) The INFO log level filter in Airflow UI now correctly displays log
messages with this logging level.</p>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-7-build-10">composer-3-airflow-3.1.7-build.10</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-6">composer-3-airflow-2.11.1-build.6</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-39">composer-3-airflow-2.10.5-build.39</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-3-airflow-2-11-1">composer-2.17.3-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-3-airflow-2-10-5">composer-2.17.3-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:
composer-3-airflow-2.9.3-build.24, composer-2.13.2-airflow-2.9.3,
composer-2.13.2-airflow-2.10.5.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>For Exadata Database Service on Exascale infrastructure, Base Database Service, and Goldengate, Oracle Database@Google Cloud adds
the following regions and zones:</p>
<ul>
<li><code>australia-southeast2-a-r2</code> (Melbourne, Australia)</li>
<li><code>europe-west8-b-r1</code> and <code>europe-west8-a-r1</code> (Milan, Italy)</li>
</ul>
<p>For a list of supported locations, see <a href="https://docs.cloud.google.com/oracle/database/docs/regions-and-zones">Supported regions and zones</a>.</p>
<h2 class="release-note-product-title">Secure Source Manager</h2>
<h3>Feature</h3>
<p>Secure Source Manager enforces a daily rate quota on the size of code
scanned for credentials per instance. The default quota limit is 1 GB per day
per instance. For more information, see <a href="https://docs.cloud.google.com/secure-source-manager/docs/quotas">Quotas and
limits</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner Graph supports a suite of
<a href="https://docs.cloud.google.com/spanner/docs/graph/graph-algorithms-overview">graph algorithms</a> covering
use cases such as fraud detection, entity resolution, and recommendations.
You can invoke graph algorithms as built-in function calls in Spanner Graph
queries. You can save your output to Cloud Storage or Spanner.
This feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: Table and image annotation in layout parser</strong></p>
<p>The table annotation and image annotation features of the layout parser are
generally available (GA).</p>
<p>You can ask the layout parser to annotate images or tables with
a descriptive block of text describing the information in the image or table.
The annotation can then be used as a source in a generated answer.
For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/parse-chunk-documents#layout-parsing">Layout
parser</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 26, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_26_2026</id>
    <updated>2026-05-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_26_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/bigquery/docs/colab-data-science-agent">Data Science Agent</a> (DSA) for
Colab Enterprise and BigQuery is now <a href="https://cloud.google.com/products/#product-launch-stages">generally
available</a> (GA).</p>
<h2 class="release-note-product-title">Cloud CDN</h2>
<h3>Feature</h3>
<p>For <a href="https://docs.cloud.google.com/load-balancing/docs/https/setting-up-global-traffic-mgmt#cdn-cache-policy">global external Application Load Balancers</a>, you can configure Cloud CDN
cache policies at various levels of a URL map, providing more granular control
over caching. You can now apply specific caching logic based on hostnames,
URL paths, HTTP headers, and query parameters. This feature is
<strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/cdn/docs/caching#cache-policies-url-maps">Cache policies in URL maps</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>For global external Application Load Balancers, you can configure Cloud CDN cache policies at
various levels of a URL map. This provides granular control over caching
policies based on criteria like hostname, URL path, HTTP headers, and query
parameters. This feature is in <strong>General availability</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/https/setting-up-global-traffic-mgmt#cdn-cache-policy">Configure a Cloud CDN cache policy</a>.</p>
<h3>Feature</h3>
<p>Frontend configuration for load balancing incoming IPv6 traffic is now supported
for the following load balancers:</p>
<ul>
<li>Regional external Application Load Balancer</li>
<li>Regional external proxy Network Load Balancer</li>
<li>Regional internal Application Load Balancer</li>
<li>Regional internal proxy Network Load Balancer</li>
<li>Cross-region internal Application Load Balancer</li>
<li>Cross-region internal proxy Network Load Balancer</li>
</ul>
<p>This feature is in <strong>Preview</strong>.</p>
<p>For more information, see the following documentation:</p>
<ul>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/forwarding-rule-concepts">Forwarding rules overview</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/ipv6">IPv6 for Application Load Balancers and proxy Network Load Balancers</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/https/convert-applb-dualstack">Convert Application Load Balancer to IPv6</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/tcp/convert-proxynetlb-dualstack">Convert Proxy Network Load Balancer to IPv6</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/proxy-only-subnets#proxy_only_subnet_create">Proxy-only subnets for Envoy-based load balancers</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Announcement</h3>
<p>Cloud Trace in Observability Analytics is generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
Observability Analytics lets you query and analyze your trace data by using SQL.
You can chart your query results, save your queries, and join your trace and
log data.</p>
<p>For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics">Query and analyze telemetry with Observability Analytics</a>.</li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics-chart">Chart SQL query results</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics-samples">Sample SQL queries</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/analytics-query-linked-dataset">Analyze trace data with BigQuery</a>.</li>
</ul>
<h3>Announcement</h3>
<p>The Observability API is generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
This API lets you configure the following:</p>
<ul>
<li>The default storage location and the default encryption key for your
trace data.</li>
<li>The observability scope.</li>
<li>A linked BigQuery dataset, which lets your use BigQuery
services to analyze your trace data.</li>
</ul>
<p>For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/scopes">Configure observability scopes for multi-project queries</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/storage-manage">Manage observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/reference/api-overview">API overview</a></li>
</ul>
<h3>Announcement</h3>
<p>Trace scopes are generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/trace-scope/create-and-manage">Create and manage trace scopes</a>.</p>
<h3>Feature</h3>
<p>The following remote MCP servers automatically generate a trace span for
<code>tools/call</code> operations. These spans can help you understand the behavior of
your agentic applications. For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/instrumentation/trace-remote-mcp-server-calls">Investigate MCP calls using Trace</a>.</p>
<ul>
<li>BigQuery</li>
<li>Cloud SQL</li>
</ul>
<h2 class="release-note-product-title">Colab Enterprise</h2>
<h3>Feature</h3>
<p><strong>Data Science Agent</strong></p>
<p><a href="https://cloud.google.com/products#product-launch-stages">Generally available</a>:
Use the Data Science Agent to automate exploratory data analysis,
perform machine learning tasks, and deliver insights from within
a Colab Enterprise notebook. To get started, see
<a href="https://docs.cloud.google.com/colab/docs/use-data-science-agent">Use the Data Science Agent</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-120-115_">cos-129-19506-120-115 <a id='"cos-arm64-129-19506-120-115"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4b67db877bccca1607f98ab4fd34f80e6245828f
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.115/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43074 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-32289,CVE-2026-32282,CVE-2026-32288,CVE-2026-27142,CVE-2025-61728,CVE-2026-27139,CVE-2026-39817,CVE-2026-39819,CVE-2025-68119,CVE-2025-61732,CVE-2026-32280,CVE-2026-25679,CVE-2026-27144,CVE-2026-32283,CVE-2026-27140,CVE-2025-61731,CVE-2026-32281,CVE-2025-61726,CVE-2025-68121,CVE-2026-27143,CVE-2026-39826,CVE-2026-39823,CVE-2026-39825,CVE-2026-33814,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-47_">cos-125-19216-395-47 <a id='"cos-arm64-125-19216-395-47"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/b82d4fb79da9ccb0fb216da3a51f977397f3193d
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.47/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-42499,CVE-2026-39820,CVE-2026-39826,CVE-2026-33814,CVE-2026-39836,CVE-2026-39823,CVE-2026-39825,CVE-2026-39817,CVE-2026-39819.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-144_">cos-121-18867-381-144 <a id='"cos-arm64-121-18867-381-144"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/49ca470354b8180a68a948c2512fb9b5f4ef8b5f
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.144/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39823,CVE-2026-39826,CVE-2026-39817,CVE-2026-39819,CVE-2026-39820,CVE-2026-39836,CVE-2026-42499,CVE-2026-39825.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-25_">cos-117-18613-613-25 <a id='"cos-arm64-117-18613-613-25"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6cd389d7730d16d15e008a822b46e2f5d450d562
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.25/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded app-containers/containerd from v1.7.29 to
v1.7.31.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-39817,CVE-2026-39825,CVE-2026-33814,CVE-2026-39819,CVE-2026-39826,CVE-2026-39823,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Filter support for Google Sites data stores (Preview)</strong></p>
<p>You can add Site URL prefix filters to Google Sites data stores in
Gemini Enterprise to include or exclude specific sites from search results.</p>
<p>This feature is in Public Preview. For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/gsites/add-filters-to-gsites-data-store">Add filters to a Google Sites data store</a>.</p>
<h3>Deprecated</h3>
<p><strong>Gemini Enterprise: Gemini Enterprise assist is deprecated</strong></p>
<p>The Gemini Enterprise assist feature is deprecated and shut down.
Users can now find comprehensive and relevant answers directly in the
Gemini Enterprise documentation.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Data store for PagerDuty (Preview)</strong></p>
<p>You can connect PagerDuty data stores to Gemini Enterprise.</p>
<p>Support for PagerDuty data stores is in Public Preview. For more information,
see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/pagerduty">Connect PagerDuty</a>.</p>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Administrator control for Gemini 3.5 Flash</strong></p>
<p>Gemini Enterprise administrators can use the feature management toggle to turn on
or turn off Gemini 3.5 Flash, controlling its visibility in the
Gemini Enterprise app chat box.</p>
<p>The feature management toggle for Gemini 3.5 Flash will not be
available after June 8, 2026. Starting June 8, 2026, Gemini 3.5 Flash
is enabled by default and cannot be turned off for users in the Gemini Enterprise
app.</p>
<p>For more information about feature controls, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>The Gemini Deep Research Agent released in Preview</strong></p>
<p>The Gemini Deep Research Agent has been released in Preview. The Gemini Deep
Research Agent is a managed AI agent that plans, executes, and synthesizes
complex, multi-step research workflows across the public web and private
enterprise data to generate comprehensive, cited reports.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/agents/use-deep-research">Use the Gemini Deep Research
Agent</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Platform Sandboxes</strong></p>
<p>Additional Agent Platform <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox">sandbox</a>
features are now available:</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/computer-use">Computer use</a> (Preview)</strong>:
Enables agents to automate browser-based tasks within an isolated web
browser environment. You can control the browser using the API or connect
directly using the Chrome DevTools Protocol (CDP).</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/custom-containers">Custom container sandboxes</a> (Preview)</strong>:
Bring your own container (BYOC) to run custom workloads with specialized
dependencies hosted in Artifact Registry.</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/manage-templates">Sandbox templates</a> (Preview)</strong>:
Define sandbox specifications as reusable templates relying on pre-warmed
pools to facilitate rapid, reliable startups.</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/manage-snapshots">Sandbox snapshots</a> (Preview)</strong>:
Save the exact state of your sandbox environment (including dependencies and
file systems) and restore it to a new sandbox.</li>
</ul>
<h3>Feature</h3>
<p><strong>Identify the agents with the most content security violations</strong></p>
<p>The <strong>Security</strong> dashboard displays the top 10 agents with the most content
violations detected by Model Armor. The list shows the agent ID of each
agent and the number of violations detected for that agent. For more
information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/monitor-content-security">Monitor content
security</a>.</p>
<h2 class="release-note-product-title">Generative AI on Vertex AI</h2>
<h3>Deprecated</h3>
<p><strong>Vertex AI Extensions deprecation</strong></p>
<p>Vertex AI Extensions is deprecated and will be shut down after November 26, 2026.
We recommend
<a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/extensions/migrate">migrating to Agent Platform</a>
to avoid service disruption.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.35</strong></p>
<p>We've released version 4.35 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where URLs copied from Microsoft Word into SMS chat sessions
were incorrectly formatted, causing links to merge with adjacent text.</p></li>
<li><p>Fixed an issue with Alvaria campaigns where the dialer didn't correctly use
the country code from the <strong>@COUNTRYCODE</strong> field when selecting the contact
number to dial.</p></li>
<li><p>Fixed an issue where live transcription didn't resume after an agent enabled
and then disabled redaction during IVR payment card collection.</p></li>
<li><p>Fixed an issue where agents couldn't upload PDF files in chat sessions.</p></li>
<li><p>Fixed an issue where end-users encountered errors or empty details when
accessing call history immediately after a call ended.</p></li>
<li><p>Fixed an issue where agents became stuck in the <code>In-call</code> status and
couldn't end calls or change their status, preventing them from handling new
interactions.</p></li>
<li><p>Fixed an issue where the deletion of the default greeting message for a
language didn't persist.</p></li>
<li><p>Fixed a web SDK issue where scheduling a call in one queue incorrectly
showed the <strong>Reschedule Call</strong> screen from a different queue.</p></li>
<li><p>Fixed an issue that occurred when a human agent invoked the payment virtual
task assistant to collect card details. When the call was transferred back
to the human agent, live transcription and sentiment analysis didn't resume.</p></li>
<li><p>Fixed an issue where HubSpot ticket creation failed when <strong>Skip CRM Account
Creation</strong> and <strong>Skip Account Lookup</strong> were enabled. This resulted in
tickets being created without an associated phone number.</p></li>
<li><p>Fixed an issue where, after transferring a call from one queue to another,
the receiving agent's desktop temporarily showed the source queue's agent
desktop layout instead of the destination queue's layout.</p></li>
<li><p>Fixed an issue where outbound Telnyx calls got stuck on the agent adapter
<strong>Connecting</strong> screen when <strong>Agent Voice Detection</strong> was enabled globally.</p></li>
<li><p>Fixed an issue where Alvaria Advanced Outreach outbound campaign batch files
weren't ingested by Contact Center AI Platform, preventing campaigns from loading
contacts.</p></li>
<li><p>Fixed an issue where a single inbound call in Salesforce created two cases.</p></li>
<li><p>Fixed an issue where the <strong>Agents</strong> dashboard showed an invalid <code>-10</code> agent
status during wrap-up and after calls.</p></li>
<li><p>Fixed an issue where Alvaria WFM Agent Performance reports displayed no
agent activity.</p></li>
<li><p>Fixed an issue where the NICE WFM exporter reported higher abandoned call
counts than Contact Center AI Platform reporting.</p></li>
<li><p>Fixed an issue where chats escalated from a virtual agent to a human agent
were dismissed shortly after assignment.</p></li>
<li><p>Fixed an issue where the <strong>Ticket URL</strong> column in the <strong>Individual Call
History CSV report</strong> was blank for newly recorded calls, preventing
customers from accessing and downloading call recordings from the report.</p></li>
<li><p>Fixed an issue where newly created teams couldn't be reordered in the
CCAI Platform portal.</p></li>
<li><p>Fixed an issue where the agent desktop <strong>Previous Interactions</strong> panel
didn't show Agent Assist summaries from past calls.</p></li>
<li><p>Fixed an issue where conversation history didn't display correctly in the
agent adapter when a chat was escalated from a virtual agent to a human
agent and then a large number of messages were sent by the end-user.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>Cloud Storage FUSE CSI driver is now supported for Google Cloud Dedicated
clusters and node pools running GKE version 1.36.0-gke.1266000 and higher. To
use the driver, you must specify the <code>custom-endpoint</code> mount option by using
either the <a href="https://docs.cloud.google.com/storage/docs/cloud-storage-fuse/cli-options#options">gcsfuse CLI</a>
or the <a href="https://docs.cloud.google.com/storage/docs/cloud-storage-fuse/config-file#format-and-fields">configuration
file</a> format.
For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/cloud-storage-fuse-csi-driver">About Cloud Storage FUSE CSI driver for
GKE</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 25, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_25_2026</id>
    <updated>2026-05-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_25_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>To monitor the efficiency of the GKE training JobSet, the following two GKE
system metrics are available in Preview:</p>
<ul>
<li><code>kubernetes.io/jobset/scheduling_goodput</code>: the fraction of time that all the
resources required to run the training JobSet are available.</li>
<li><code>kubernetes.io/jobset/proxy_runtime_goodput</code>: the fraction of time that all
required accelerators are productive. This metric provides an estimate of the
real runtime goodput.</li>
</ul>
<p>For details about GKE metrics, see <a href="https://docs.cloud.google.com/monitoring/api/metrics_kubernetes#kubernetes-kubernetes">Kubernetes
metrics</a>.
For details about goodput metrics that are used to measure efficiency, see
<a href="https://docs.cloud.google.com/tpu/docs/goodput#jobset-dashboard">Monitor goodput with the ML Goodput Measurement
library</a>.</p>
<p>You can also view these new GKE metrics in the <a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/tpu-multislice-kueue#monitor_the_workloads">JobSet monitoring dashboard</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Data products in Knowledge Catalog is
Generally Available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
A data product serves as a logical, curated package of data assets and context
designed to solve a specific business problem.</p>
<p>This release includes the following new features:</p>
<ul>
<li><p><strong>Approval workflows for data product consumption:</strong> Data product consumers
can browse published data products, submit access requests, and track their
status. Data product owners can track, approve, or reject access requests
using the Google Cloud Console or the API. For more information, see
<a href="https://cloud.google.com/dataplex/docs/use-data-products">Use data products</a>
and
<a href="https://cloud.google.com/dataplex/docs/manage-data-products">Manage data products</a>.</p></li>
<li><p><strong>Automated documentation and insights:</strong> Data product owners can leverage
Knowledge Catalog data insights and Gemini to automatically generate sample
queries, business insights, and documentation templates for data products.
For more information, see
<a href="https://cloud.google.com/dataplex/docs/create-data-products">Create data products</a>.</p></li>
<li><p><strong>Service account support:</strong> Data product owners can configure service
accounts in access groups, and data product consumers can request access for
their service accounts. For more information, see
<a href="https://cloud.google.com/dataplex/docs/create-data-products">Create data products</a>.</p></li>
<li><p><strong>Remote Model Context Protocol (MCP) server support (Preview)</strong> Data
applications and AI agents can programmatically interact with data products.
By deploying the Knowledge Catalog remote MCP server, developers can create
data products, discover data products, and inspect data product metadata from
external IDEs and LLM clients. For more information, see
<a href="https://cloud.google.com/dataplex/docs/use-data-products#mcp-server">Access data products using Model Context Protocol</a>.</p></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine): The following subminor image versions announced on <a href="https://docs.cloud.google.com/managed-spark/docs/release-notes#May_19_2026">May 19, 2026</a> have been rolled back:</p>
<ul>
<li>2.2.82-debian12, 2.2.82-rocky9, 2.2.82-ubuntu22, 2.2.82-ubuntu22-arm</li>
</ul>
]]>
    </content>
  </entry>

</feed>
