Back to feed
Security: On May 20, 2026, we published a security bulletin for Apigee.
On May 20, 2026, we published a security bulletin for Apigee.
A vulnerability was found in Apigee (CVE-2026-2264) where the IntegrationRegion parameter in the SetIntegrationRequest policy lacks validation, allowing for Server-Side Request Forgery (SSRF) and service account token exfiltration. The issue arises when an attacker can control a flow variable used for IntegrationRegion, leading to requests being sent to an attacker-controlled host with the service account token.
Security bulletin published: GCP-2026-034