The week in one paragraph
217 notes across 61 products and five days, against 132 last week — and the security bulletins returned after two quiet weeks, with three disclosures all landing on Monday against the same product. But the single most consequential line is a Cloud SQL note tagged Breaking, which removed an existing permission from three predefined roles, two of which are the basic roles that large estates hand out widely. Alongside it, two monitoring agents reached end of support on the same day, and Cloud Service Mesh put both of its ISTIOD control planes on a deprecation clock that ends with workloads failing rather than merely losing support. It was a week about things being taken away, which is the kind of week that costs you later if you only read the feature announcements.
A permission removed from roles you already granted
The Cloud SQL note is short enough to quote and important enough to read twice: to improve security, removed the cloudsql.instances.export permission from the following roles — Cloud SQL Viewer (roles/cloudsql.viewer), Basic Reader (roles/reader) and Basic Viewer (Legacy) (roles/viewer). The remedy offered is also explicit: to retain export capabilities, assign the Cloud SQL Editor role, or update custom roles to include the permission.
Two things make this the item of the week. The first is that it is a reduction in what an existing binding grants, applied to roles already in use, which means nothing in your Terraform, your allow policy or your change log records that anything happened — the binding still says roles/viewer and now means slightly less. The second is the blast radius: this is not an obscure role. Basic Viewer and Basic Reader are the roles that get granted at project and organisation scope when somebody wants "read-only for the auditors". Any export job, backup script or data pipeline running under a basic role rather than a Cloud SQL role stops working, and the error will be a permission denial on an operation nobody changed.
Thursday’s post in this series quoted Google’s own warning that the permissions within these roles can change without notice, about service agent roles. The Cloud SQL note is the same mechanism applied to ordinary predefined roles, in production, on a Monday. The lesson is not that Google was wrong to tighten it — a viewer role granting data export is exactly the sort of thing that should be fixed. It is that the contents of a predefined role are a moving target, so anything whose correctness depends on a specific permission should name that permission, in a custom role, rather than inheriting it from a bundle somebody else maintains.
Worth pairing with a second Breaking note from Cloud Logging on the same day: only platform services can write log entries to billing accounts. If anything you run writes to a billingAccounts/ log name, it stops.
Three Application Integration vulnerabilities
After two weeks with no bulletins at all, three arrived on Monday, all against Application Integration and all with a fix date already in the past:
| Bulletin | Class | Component | Affected versions |
|---|---|---|---|
| GCP-2026-066 | Confused Deputy | Email Task | prior to June 30, 2026 |
| GCP-2026-065 | Deserialization of Untrusted Data | JavaScript Task | prior to June 28, 2026 |
| GCP-2026-064 | Incorrect Authorization | task configuration | prior to June 17, 2026 |
The pattern is worth noting even if you do not use the product. All three are in the parts of an integration platform that execute or address things on your behalf — a task that sends mail, a task that runs JavaScript, and the configuration that decides what a task may do. A Confused Deputy issue in an email component and an Incorrect Authorization issue in task configuration are both, in substance, the service acting with its own authority where it should have been acting with yours. That is the same class of problem the service agent material in this series has been circling, arriving here as three CVE-grade findings in one product on one day.
Separately, Apigee shipped security fixes across several components, including CVE-2026-84445 in apigee-connect-agent, and Agent Platform Workbench shipped a bulk security patch remediating Critical and High-severity CVEs in the Workbench custom container images. Neither carries a numbered bulletin; both are in the inventory below.
Two agents retired, one mesh on a clock
Monday was an end-of-support day for the old observability agents. The legacy Logging agent has officially reached its end of support, and so has the legacy Monitoring agent, both with the same consequence: all standard maintenance and regular bug fixes for the agent have ceased. This is end of support rather than shutdown — the agents keep running — but they are now unpatched software collecting your logs and metrics, which is a worse position than the wording suggests.
The Cloud Service Mesh deprecations are the ones to put in a calendar, because both ISTIOD control planes went onto the same clock. Cloud Service Mesh support for the in-cluster ISTIOD control plane on Google Kubernetes Engine (GKE) on Google Cloud is deprecated as of September 28, 2026, and support will end on March 1, 2028 — and the identical sentence appears for the managed ISTIOD control plane. Google is transitioning managed Cloud Service Mesh to the TRAFFIC_DIRECTOR control plane.
For the in-cluster plane: after March 1, 2028, in-cluster control plane components on GKE will not receive updates, security patches, or support from Google Cloud. That is the familiar unsupported-but-running outcome. For the managed plane the note goes further — workload sidecars on unmodernized clusters will fail and be unable to receive or send requests. That is not degradation, it is a data-plane outage, and the guidance is explicit that you must modernize your clusters by March 1, 2028. Seventeen months is plenty of time and exactly the amount of time that gets spent.
Backup and DR added a third dated retirement, for the legacy appliance management console: after September 30, 2027, you will no longer be able to run new backups using the legacy stack, while support for standard restores, exports, and migrations using the legacy appliance management console continues till March 31, 2028. Note the asymmetry — the ability to take new backups ends six months before the ability to restore old ones, which is the right way round but worth planning against rather than discovering.
Platform, data and the rest
BigQuery had the busiest week of any product at 13 notes, and the one with the broadest reach is governance rather than query: the BigQuery Security center is now available in the Google Cloud console, generally available, for analysing a data security profile and managing row- and column-level security policies and policy tags. If you have been assembling that picture by hand, this is the console surface for it.
Container Optimized OS contributed 12 notes, the usual package-upgrade run, rolled up in the inventory rather than listed line by line. Gemini Enterprise and its Agent Platform together carried 14 across two product lines, and Apigee across its three variants carried 9. Everything else is thinly spread: 61 products with a note, and most of them with one or two.
What I would act on
- Search your IAM bindings for the basic roles, then search your automation for Cloud SQL export. The permission removal is live and silent. Anything exporting a Cloud SQL instance under
roles/viewer,roles/readerorroles/cloudsql.vieweris now broken, and the fix is a Cloud SQL role or a custom role naming the permission explicitly. - Check whether anything you own writes log entries to a billing account. The Breaking note is unambiguous and the failure will look like a logging bug rather than a policy change.
- If you use Application Integration, confirm your version is past June 30, 2026. Three bulletins, three components that act on your behalf, all with fixes already shipped.
- Put March 1, 2028 in a calendar for Cloud Service Mesh, with a note that the managed plane fails rather than merely ages. Then start the compatibility review, because the feature-parity check against
TRAFFIC_DIRECTORis the part that takes the time. - Migrate off the legacy Logging and Monitoring agents. They stopped receiving bug fixes on Monday. This one has no deadline attached, which is exactly why it will sit.
Complete inventory — all 217 notes
How this inventory reconciles
Google Cloud published 217 notes across 61 products and 5 days in this window, read from 4 feeds. Every one of them is accounted for below, in exactly one place:
| Bucket | Notes | Why |
|---|---|---|
| Listed individually | 139 | Every note that is its own distinct fact. |
| Published under several products | 17 | 2 texts issued once per runtime or service; shown once, with the products named. |
| Repeating runs, rolled up | 61 | 2 product/type runs where the same text recurs once per release. Summarised with the full identifier list, not deduplicated. |
| Total | 217 |
Repeating runs, rolled up
- Container Optimized OS (42 notes) — Fixed42 notes, across 4 releases (cos-117-18613-767-2, cos-121-18867-624-2, cos-125-19216-700-7, cos-dev-138-20162-0-0). 30 distinct texts, each repeated once per release and counted individually:
- Added support for NVIDIA driver v580.178.04.
- Added support for NVIDIA driver v595.91.07.
- Added support for bare metal TPUs.
- Fixed a bug which could cause DOCA workloads to fail to initialize.
- Fixed an issue where temporary efivarfs mounts under /tmp could persist after boot.
- Upgraded app-admin/google-guest-configs to v20260911.00.
- Upgraded app-admin/oslogin to v20260902.00.
- Upgraded app-admin/sosreport to v4.12.0.
- Upgraded app-arch/bzip2 to v1.0.8-r5.
- Upgraded app-arch/unzip to v6.0_p31.
- Upgraded app-arch/xz-utils to v5.8.4.
- Upgraded app-arch/zstd to v1.5.7-r1.
- Upgraded app-misc/ca-certificates to v20260601.3.112.5.
- Upgraded chromeos-base/chromeos-common-script to v0.0.1-r675.
- Upgraded chromeos-base/debugd-client to v0.0.1-r2742.
- Upgraded chromeos-base/google-breakpad to v2026.09.04.193747-r281.
- Upgraded chromeos-base/power_manager-client to v0.0.1-r2976.
- Upgraded chromeos-base/session_manager-client to v0.0.1-r2838.
- Upgraded containerd and containerd-test to v2.4.1.
- Upgraded dev-lang/luajit to v2.1.1787165859.
- Upgraded dev-libs/expat to v2.8.4.
- Upgraded dev-libs/json-c to v0.19-r2.
- Upgraded dev-libs/libgcrypt to v1.12.3-r1.
- Upgraded dev-libs/libpcre2 to v10.48.
- Upgraded dev-libs/libverto to v0.3.2-r1.
- Upgraded dev-libs/libxml2 to v2.15.4.
- Upgraded dev-libs/popt to v1.19-r1.
- Upgraded dev-libs/xxhash to v0.8.3-r2.
- Upgraded dev-python/pyjwt to v2.14.0.
- Upgraded sys-devel/binutils-config to v5.6.
- Container Optimized OS (19 notes) — Change19 notes, across 6 releases (cos-117-18613-767-2, cos-121-18867-624-2, cos-125-19216-700-7, cos-129-19506-505-8, cos-133-19999-44-85, cos-dev-138-20162-0-0). 12 distinct texts, each repeated once per release and counted individually:
- Enabled automatic loading of RDMA kernel modules when CX-9 devices are detected.
- Ensure time sync prior to TLS handshake.
- Runtime sysctl changes: Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068
- Updated cos-gpu-installer to v2.7.8.
- Updated google-guest-configs to v20260918.00.
- Updated the Linux kernel to v6.18.51.
- cos-117-18613-767-2 Kernel Docker Containerd GPU Drivers COS-6.6.157 v24.0.9 v1.7.34 See List
- cos-121-18867-624-2 Kernel Docker Containerd GPU Drivers COS-6.6.157 v27.5.1 v2.0.10 See List
- cos-125-19216-700-7 Kernel Docker Containerd GPU Drivers COS-6.12.110 v27.5.1 v2.2.7 See List
- cos-129-19506-505-8 Kernel Docker Containerd GPU Drivers COS-6.12.110 v27.5.1 v2.2.7 See List
- cos-133-19999-44-85 Kernel Docker Containerd GPU Drivers COS-6.18.48 v29.4.3 v2.4.1 See List
- cos-dev-138-20162-0-0 Kernel Docker Containerd GPU Drivers COS-6.18.51 v29.4.3 v2.4.1 See List
One change, published under several products
- FeatureApp Engine permanently blocks insecure traffic with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom…Published under 14 products: App Engine flexible environment .NET, App Engine flexible environment Go, App Engine flexible environment Java, App Engine flexible environment Node.js, App Engine flexible environment PHP, App Engine flexible environment Python, App Engine flexible environment Ruby, App Engine flexible environment custom runtimes, App Engine standard environment Go, App Engine standard environment Java, App Engine standard environment Node.js, App Engine standard environment PHP, App Engine standard environment Python, App Engine standard environment Ruby.
- BreakingTo improve security, removed the cloudsql.instances.export permission from the following roles: Cloud SQL Viewer ( roles/cloudsql.viewer ) Basic Reader ( roles/…Published under 3 products: Cloud SQL for MySQL, Cloud SQL for PostgreSQL, Cloud SQL for SQL Server.
Everything else, by product
API Gateway — 2
- FeatureConfigure streaming for LLM responses and other traffic You can now create API Gateway gateways that stream requests and responses instead of buffering them. Th…Tue 29 Sep
- FeatureAuthenticate MCP tool discovery with an API key API key authentication is now supported for the Model Context Protocol (MCP) tools/list method. You can name an…Wed 30 Sep
Agent Platform Workbench — 6
- Change20260927.00_p0 ReleaseMon 28 Sep · 20260927.00_p0
- ChangeInstalled latest packages from upstream dependencies.Mon 28 Sep · 20260927.00_p0
- Change20260927.00_p0 ReleaseMon 28 Sep · 20260927.00_p0
- ChangeInstalled latest packages from upstream dependencies.Mon 28 Sep · 20260927.00_p0
- SecurityBulk security patch remediating Critical and High-severity CVEs in the Workbench custom container images.Mon 28 Sep · 20260927.00_p0
- SecurityBulk security patch remediating Critical and High-severity CVEs in the Workbench custom container images.Mon 28 Sep · 20260927.00_p0
Apigee API hub — 1
- FeatureAI performance and Tool performance dashboards in API insights API insights in API hub now includes two dashboards for AI and agent traffic: AI performance repo…Wed 30 Sep
Apigee X — 3
- AnnouncementOn October 2, 2026, we released an updated version of Apigee (1-18-0-apigee-6). Note: Rollouts of this release began today and can take four or more business da…Fri 02 Oct
- FixedBug ID Description 432315283 Fixed a multi-certificate truststore so that its trust anchors take effect without a Message Processor restart when features.trusts…Fri 02 Oct
- SecurityBug ID Description 564386425 Security fix for Apigee. Upgraded the Apigee ingress gateway (ASM) to patch security vulnerabilities. 561666530 Security fix for Ap…Fri 02 Oct
Apigee hybrid — 5
- Announcementv1.17.1 On September 30, 2026 we released an updated version of the Apigee hybrid software, v1.17.1. For information on upgrading, see Upgrading Apigee hybrid t…Wed 30 Sep · v1.17.1
- ChangeThe Apigee operator's Kubernetes manager role now includes the core endpoints permission. In v1.17.1, the Apigee operator's manager role is granted the core ( "…Wed 30 Sep · v1.17.1
- FeatureExternal Cassandra datastore support Apigee hybrid v1.17.1 adds support for connecting an Apigee hybrid runtime to a Cassandra datastore that runs in a separate…Wed 30 Sep · v1.17.1
- FixedFixed in this release Bug ID Description 565753858 Fixed an issue where the apigee-mcp-server controller dropped pod-level volumes configured on the mcpServer c…Wed 30 Sep · v1.17.1
- SecurityBug ID Description N/A Security fixes for apigee-connect-agent . This addresses the following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-hybrid…Wed 30 Sep · v1.17.1
Application Integration — 3
- SecurityA Confused Deputy vulnerability was discovered in the Email Task component in Application Integration versions prior to June 30, 2026. For more information, see…Mon 28 Sep
- SecurityA Deserialization of Untrusted Data vulnerability was discovered in the JavaScript Task in Application Integration versions prior to June 28, 2026. For more inf…Mon 28 Sep
- SecurityAn Incorrect Authorization vulnerability was discovered in the task configuration in Application Integration versions prior to June 17, 2026. For more informati…Mon 28 Sep
Backup and DR — 1
- DeprecatedSupport for backing up and restoring workloads managed via the legacy appliance management console is deprecated. Key milestones for this deprecation include th…Wed 30 Sep
BigQuery — 13
- FeatureThe BigQuery Data Transfer Service MCP server is now Generally Available (GA).Mon 28 Sep
- FeatureYou can now write the output rows produced by BigQuery continuous queries directly into Apache Iceberg managed tables . This lets you continuously process strea…Mon 28 Sep
- FeatureThe AI.KEY_DRIVERS function is now generally available (GA). You can use the AI.KEY_DRIVERS function to identify segments of data that cause statistically signi…Tue 29 Sep
- FeatureYou can query the INFORMATION_SCHEMA.FAILOVER_HISTORY view to retrieve a near real-time list of failover events for reservations within an administration projec…Tue 29 Sep
- FeatureThe BigQuery Security center is now available in the Google Cloud console. You can use the Security center to analyze your data security profile, create and man…Wed 30 Sep
- FeatureBigQuery jobs explorer layout and filtering improvements, including status counts in the filter bar, resource grouping , and timeline metric charts , are genera…Wed 30 Sep
- FeatureYou can now use the OBJ.LIST function to perform spontaneous discovery and analysis of unstructured data. The OBJ.LIST function returns a table of metadata and…Wed 30 Sep
- FeatureYou can now view the UPDATE , DELETE , MERGE , and EXPORT execution steps in your query plans.Wed 30 Sep
- ChangeAn updated version of the Simba JDBC driver for BigQuery is now available.Thu 01 Oct
- FeatureChatting with graphs in conversational analytics is now generally available . You can use a combination of multiple graphs, tables, views, and UDFs as data sour…Thu 01 Oct
- FeatureBigQuery pipelines provides support for automated metadata enrichment and Knowledge Catalog data quality scorecard integration. In addition, the Data Engineerin…Thu 01 Oct
- FeatureThe Rust SDK for BigQuery is now generally available (GA).Fri 02 Oct
- FeatureThe Data Engineering Agent now supports the gemini-3.7-flash model for the us , eu , and global multi-regional endpoints.Fri 02 Oct
Bigtable — 1
- FeatureYou can use Google Cloud Data Agent Kit to browse Bigtable instances and tables, design schemas, and run GoogleSQL queries from your IDE or coding agent. This f…Thu 01 Oct
Blog — 20
- PostAccelerating agentic RL and evaluation research velocity with 45x faster GKE Agent SandboxTue 29 Sep
- PostGraph Workflows in ADK: Everything You Need to KnowTue 29 Sep
- PostGoogle Cloud partners deliver new security agents and AI defenses with Gemini EnterpriseTue 29 Sep
- PostDefending at machine speed: Securing the public sector in the agentic eraTue 29 Sep
- PostWhat’s new in AI infrastructure and orchestration in SeptemberWed 30 Sep
- PostCloud CISO Perspectives: How cybersecurity startups can win CISOsWed 30 Sep
- PostEmpower your agents with the Google Cloud CLI remote MCP serverWed 30 Sep
- PostSpanner Omni, now GA: A distributed, multi-model database that you can deploy anywhereWed 30 Sep
- PostVulnerability Discovery and Exploitation Trends in the AI EraWed 30 Sep
- PostData Agent Kit is now GA: Bring Google Data Cloud to any coding agentWed 30 Sep
- PostEnabling Cloud Storage end-to-end checksums for improved data integrity and durabilityThu 01 Oct
- PostAccelerating analytics: PayPal’s journey with Managed Service for Apache SparkThu 01 Oct
- PostDemocratizing Managed Lustre with lower cost and frictionless developmentThu 01 Oct
- PostThe future of browser-based security: Leveraging browser data for proactive defenseThu 01 Oct
- PostIntroducing the Server Side Cloud Swift SDKThu 01 Oct
- PostAI21 achieves an 83% reduction in time-to-start for AI workloads with AI HypercomputerFri 02 Oct
- PostWhat’s new with Google CloudFri 02 Oct
- PostAnnouncing Spanner queues: Transactional messaging for agentic workloads and beyondFri 02 Oct
- PostGKE CPU startup boost: Accelerate app starts without over-provisioningFri 02 Oct
- PostHow to implement long-term AI agent memory in AlloyDB and Memorystore for ValkeyFri 02 Oct
Cloud Asset Inventory — 1
- FeatureThe following resource types are publicly available through the ExportAssets , ListAssets , BatchGetAssetsHistory , QueryAssets , Feed , and Search ( SearchAllR…Mon 28 Sep
Cloud Interconnect — 1
- FeatureNetwork Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) is Generally Available .Tue 29 Sep
Cloud Load Balancing — 2
- FeatureZonal network endpoint groups (NEGs) with GCE_VM_IP and GCE_VM_IP_PORT endpoints support IPv6-only endpoints that reference IPv6-only or dual-stack Compute Engi…Mon 28 Sep
- FeatureA new quota system governing the configuration size of Application Load Balancers is now generally available . This update increases the individual URL map size…Wed 30 Sep
Cloud Logging — 2
- BreakingOnly platform services can write log entries to billing accounts. These logs have names with the format billingAccounts/[BILLING_ACCOUNT_ID]/logs/[LOG_ID] . For…Mon 28 Sep
- DeprecatedThe legacy Logging agent has officially reached its end of support. All standard maintenance and regular bug fixes for the agent have ceased. We recommend migra…Mon 28 Sep
Cloud Monitoring — 2
- DeprecatedThe legacy Monitoring agent has officially reached its end of support. All standard maintenance and regular bug fixes for the agent have ceased. We recommend mi…Mon 28 Sep
- AnnouncementThe application topology graph is now generally available (GA) . This graph helps you to understand relationships between applications, services, and workloads,…Wed 30 Sep
Cloud NAT — 2
- FeaturePreview : Cloud NAT gateways for Private NAT support source-based NAT rules for IPv4 addresses.Mon 28 Sep
- FeatureGeneral Availability : Cloud NAT gateways for Private NAT support IPv6 to IPv4 network address translation. For more information, see NAT64 in Private NAT .Fri 02 Oct
Cloud Product Registry API — 1
- FeatureCloud Product Registry is now generally available (GA) The Cloud Product Registry API is now generally available (GA) . The Cloud Product Registry API serves as…Mon 28 Sep
Cloud Run — 2
- FeatureCreate custom URLs , like example.cloud.run , that are easy to remember and globally available for your Cloud Run services. No DNS configuration, load balancers…Mon 28 Sep
- FeatureSupport for specifying custom target CPU or concurrency utilization using scaling controls is in General Availability (GA) .Tue 29 Sep
Cloud SQL for MySQL — 2
- ChangeCloud SQL for MySQL 9.7.1 is upgraded to MySQL 9.7.2. For more information, see the MySQL 9.7.2 Release Notes and Cloud SQL database versions .Mon 28 Sep
- ChangeCloud SQL for MySQL 8.4.10 is upgraded to MySQL 8.4.11. For more information, see the MySQL 8.4.11 Release Notes and Cloud SQL database versions .Mon 28 Sep
Cloud SQL for PostgreSQL — 1
- ChangeYou can use the pgAudit extension to prevent string literals that might indicate sensitive information, such as passwords and secrets, from appearing in your lo…Tue 29 Sep
Cloud Service Mesh — 2
- DeprecatedCloud Service Mesh support for the in-cluster ISTIOD control plane on Google Kubernetes Engine (GKE) on Google Cloud is deprecated as of September 28, 2026, and…Mon 28 Sep
- DeprecatedCloud Service Mesh support for the managed ISTIOD control plane on Google Kubernetes Engine (GKE) on Google Cloud is deprecated as of September 28, 2026, and su…Mon 28 Sep
Cloud Storage — 1
- FeatureCloud Storage client libraries now provide automated, end-to-end checksumming by default for object read and write operations to help maintain data integrity fr…Wed 30 Sep
Cloud Tasks — 1
- FeatureCloud Tasks support for the following is generally available ( GA ): Set retry parameters when creating a task and override the queue-level retry configuration…Wed 30 Sep
Compute Engine — 7
- FeatureAllowlisted GA : You can expose the host ID of a Compute Engine instance to verify its physical location in relation to other compute instances in your Google C…Mon 28 Sep
- FeatureGenerally available : The C4D machine series supports Hyperdisk Throughput. For more information, see About Hyperdisk Throughput and Hyperdisk Throughput perfor…Mon 28 Sep
- AnnouncementInterface-based versioning (IBV) for the Compute Engine API is now generally available. IBV lets you call a specific, date-based API version so you can adopt AP…Tue 29 Sep
- FeatureGenerally available : Compute Engine API version 2026-09-01 is now generally available. In this version, aggregatedList methods return partial results by defaul…Tue 29 Sep
- FeaturePreview : Compute Engine API version 2026-10-01-preview is now available in Preview. In this version, the quotas field is no longer available in responses from…Tue 29 Sep
- FeatureGenerally available : You can create a standard or archive snapshot of a disk and protect the snapshot with a customer-managed encryption key (CMEK), even if th…Tue 29 Sep
- FeatureGenerally available : You can specify a 120-second preemption notice duration while creating Spot VMs. Use this feature for workloads on Spot VMs where you want…Wed 30 Sep
Container Optimized OS — 12
- AnnouncementThis is an LTS Refresh release.Mon 28 Sep · cos-dev-138-20162-0-0
- AnnouncementThis is an LTS Refresh release.Mon 28 Sep · cos-125-19216-700-7
- AnnouncementThis is an LTS Refresh release.Mon 28 Sep · cos-117-18613-767-2
- AnnouncementThis is an LTS Refresh release.Mon 28 Sep · cos-121-18867-624-2
- FeatureAdded support for loading the CephFS kernel driver.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityFixed CVE-2026-0864 in dev-lang/python.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityUpgraded net-misc/rsync to version 3.5.0. This fixes CVE-2026-53791, CVE-2026-53784, CVE-2026-53786, CVE-2026-53789, CVE-2026-53795, CVE-2026-53797, CVE-2026-53…Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityFixed CVE-2026-15308 in dev-lang/python.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityFixed CVE-2026-0864 in dev-lang/python.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityFixed CVE-2026-56391 in sys-apps/coreutils.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityFixed CVE-2026-90054 in the Linux kernel.Mon 28 Sep · cos-dev-138-20162-0-0
- SecurityUpgraded net-misc/rsync to version 3.5.0. This fixes CVE-2026-53791, CVE-2026-53784, CVE-2026-53786, CVE-2026-53789, CVE-2026-53795, CVE-2026-53797, CVE-2026-53…Mon 28 Sep · cos-dev-138-20162-0-0
Dataform — 2
- FeatureExtended access options and user credentials authentication for running and scheduling Dataform workflows are now generally available (GA).Mon 28 Sep
- FeatureDataform provides support for automated metadata enrichment and Knowledge Catalog data quality scorecard integration for Dataform workflows and BigQuery pipelin…Thu 01 Oct
Datastream — 1
- FeatureDatastream now supports partial backfill for SQL Server, Spanner, Oracle, PostgreSQL, and MySQL sources. Partial backfill lets you load a specific subset of dat…Wed 30 Sep
Eventarc — 1
- FeatureEventarc support for creating triggers for direct events from Firebase Authentication is available in Preview .Wed 30 Sep
Gemini Enterprise — 5
- FeatureGemini Enterprise: Configure granular access controls for apps and data stores Administrators can configure granular, resource-level Identity and Access Managem…Mon 28 Sep
- FeatureGemini Enterprise: Support for new actions (Public Preview) Support for new actions is available in Public Preview for the following data store: Microsoft Outlo…Tue 29 Sep
- FeatureGemini Enterprise: New data stores (Preview) The following data stores are available in Gemini Enterprise: D&B Finance Analytics Omni Analytics Zapier These dat…Tue 29 Sep
- FeatureGemini Enterprise: Gemini 3.8 Flash is the default model for AlphaEvolve AlphaEvolve experiments can now generate candidate programs with Gemini 3.7 Flash and G…Tue 29 Sep
- FeatureGemini Enterprise: Federated query mode for Data Cloud connectors and Knowledge Catalog integration (Preview) Federated query mode is available in Preview for t…Fri 02 Oct
Gemini Enterprise Agent Platform — 9
- FeatureAnthropic's Claude Sonnet 5.5 Claude Sonnet 5.5 is available in Model Garden.Mon 28 Sep
- FeatureProvisioned Throughput: Support for changing order scope and increasing term Provisioned Throughput now directly supports from the self service console the abil…Mon 28 Sep
- FeatureGemini 3 models supported by the Interactions API in Preview Gemini 3 models are supported by the Interactions API in Preview on Gemini Enterprise Agent Platfor…Mon 28 Sep
- FeatureGemini 3.8 Flash TTS and Gemini 3.8 Flash-Lite TTS (Preview) Gemini 3.8 Flash TTS and Gemini 3.8 Flash-Lite TTS are available in Preview on the global endpoint.…Mon 28 Sep
- FeatureCustom denial messages for semantic governance policies You can now configure a fixed Denial message on a semantic governance policy to show end users when the…Tue 29 Sep
- FeatureCloud Trace integration with Agent Gateway (Preview) Agent Gateway integrates with Cloud Trace in Preview to provide end-to-end request observability for agent…Wed 30 Sep
- FeaturexAI's Grok 4.7 Grok 4.7 is available in Preview in Model Garden.Wed 30 Sep
- FeatureThe App Topology API that provides agent topologies in Gemini Enterprise Agent Platform is now generally available This launch introduces the following changes:…Wed 30 Sep
- FixedCodeMender updates (v0.11.0) This release introduces updates to CodeMender: Tiered location configuration : Added support for configuring the service location u…Wed 30 Sep
Google Cloud Contact Center as a Service — 1
- AnnouncementHeadless mobile SDK The headless mobile SDK, for Android and iOS, is now available. With this SDK, you can embed the capabilities of Google Cloud CCaaS into you…Wed 30 Sep
Google Cloud VMware Engine — 1
- FeatureGenerally available : Bring Your Own License (BYOL) license management for Google Cloud VMware Engine is generally available (GA). BYOL license management lets…Thu 01 Oct
Google Kubernetes Engine — 4
- FeatureThe storage-optimized Z4D machine series is available with GKE clusters running 1.36.3-gke.1244000 or later. You can use Z4D machine types in Standard or Autopi…Mon 28 Sep
- FeatureGKE now automatically applies protection tier labels to TPU node pools created from Compute Engine reservations. Depending on your configuration, GKE adds: Node…Wed 30 Sep
- FeatureYou can use Vertical Pod Autoscaler (VPA) with Horizontal Pod Autoscaler (HPA) to automatically optimize container CPU requests for workloads that scale replica…Fri 02 Oct
- IssueIn GKE control plane versions 1.36.3-gke.1244000 and later, Cloud Storage FUSE CSI driver ( gcsfusecsi-node ) DaemonSet Pods fail to start on specific node pool…Fri 02 Oct
Google SecOps — 1
- FeatureExpanded read-only permissions for Chronicle API Restricted Data Access Viewer Google SecOps has updated the predefined Chronicle API Restricted Data Access Vie…Wed 30 Sep
Looker — 2
- AnnouncementThe latest versions in the Looker (Google Cloud core) release channels are beginning deployment as follows: Latest version in the Rapid channel: Looker 26.18 La…Tue 29 Sep
- FeatureEnhanced observability metrics, including user engagement and estimated token usage data on the Token usage tab of the Conversational Analytics System Activity…Wed 30 Sep
Memorystore for Valkey — 1
- FeatureYou can use App Design Center to create instances. This feature is generally available .Wed 30 Sep
Model Armor — 1
- FeatureTemplate-specific exclusion rules are available in Preview . This feature lets you configure dictionary (word and phrase lists) and regular expression rules to…Mon 28 Sep
Network Connectivity Center — 2
- FeatureNetwork Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) is Generally Available . Billing for Partner Cross-…Tue 29 Sep
- FeatureNetwork Connectivity Center supports site-to-site data transfer in the following country: PolandFri 02 Oct
Network Intelligence Center — 2
- AnnouncementNetwork Services Monitoring is available in Preview . Network Services Monitoring visualizes communication paths and network metrics for Google Kubernetes Engin…Thu 01 Oct
- FeatureCloud Network Insights supports using Google Cloud CLI commands to download Microsoft Azure and Amazon Web Services (AWS) Monitoring Point installation bundles.Thu 01 Oct
Pub/Sub — 1
- FeatureYou can use Gemini Enterprise to generate code for user-defined function (UDF) single-message transforms (SMTs). For more information, see Create a UDF SMT .Thu 01 Oct
SAP on Google Cloud — 1
- AnnouncementHyperdisk sizing widget for SAP HANA To view Hyperdisk-based disk configurations that help you meet SAP HANA size and performance requirements, use the sizing w…Tue 29 Sep
Secure Source Manager — 1
- FeatureSecure Source Manager webhooks now support service account authorization. For more information, see Webhooks overview and Set up webhooks .Tue 29 Sep
Security Command Center — 2
- FeatureRisk Engine detects and reports reasoning engines that can modify IAM policies and perform lateral movement. These findings are generated as a toxic combination…Mon 28 Sep
- FeatureEvent Threat Detection integrates with Sensitive Data Protection to enrich findings that affect sensitive resources. For more information, see Sensitive data en…Tue 29 Sep
Security bulletin — 3
- GCP-2026-064Published: 2026-09-28 Description Description Severity Notes An Incorrect Authorization vulnerability was discovered in the task configuration in Application In…Mon 28 Sep
- GCP-2026-065Published: 2026-09-28 Description Description Severity Notes A Deserialization of Untrusted Data vulnerability was discovered in the JavaScript Task in Applicat…Mon 28 Sep
- GCP-2026-066Published: 2026-09-28 Description Description Severity Notes A Confused Deputy vulnerability was discovered in the Email Task component in Application Integrati…Mon 28 Sep
Storage Transfer Service — 1
- FeatureStorage Transfer Service now supports transferring data from multiple containers within a Microsoft Azure Storage account in a single transfer job. For more inf…Mon 28 Sep
VPC Service Controls — 3
- FeatureVPC Service Controls feature: Support for using Google Cloud folders and organizations as resources in ingress and egress rules is generally available . With th…Wed 30 Sep
- FeatureVPC Service Controls feature : Folder membership support in VPC Service Controls service perimeters is generally available . You can configure Google Cloud fold…Wed 30 Sep
- FeaturePreview stage support for the following integration: Universal LedgerWed 30 Sep
Comments