Cloud-Plattformen · 25.07.2026, 15:30 UTC
July 22, 2026
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Cloud-Plattformen |
| Quelle | Google Cloud Release Notes ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-15810. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Google Distributed Cloud (software only) for VMware Announcement Google Distributed Cloud (software only) for VMware 1.35.300-gke.87 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud 1.35.300-gke.87 runs on Kubernetes v1.35.3-gke.400. If you are using a third-party storage vendor, check the Google Distributed Cloud-ready storage partners document to make sure the storage vendor has already passed the qualification for this release. After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform. Fixed The following issues were fixed in 1.35.300-gke.87:
Fixed an issue where upgrading a user cluster with Anthos Network Gateway (ANG) enabled to an Advanced Cluster would stall or fail. Previously, the upgrade process attempted to modify immutable spec.selector fields on existing ANG resources. The upgrade operator now preserves existing label selectors during reconciliation so that V1 to V2 cluster migrations complete successfully.
Looker Security A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account. Both Looker-hosted and self-hosted instances were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. What should I do? For Looker-hosted instances, no action is …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- high CISA Adds Four Known Exploited Vulnerabilities to Catalog
- info Platform Engineering ROI: What it costs to build your own platform
- high Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
- info Toy Ghouls’ new toy: the GenieLocker ransomware