The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.
You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
September 18, 2026
Cloud Load BalancingManaged workload identity for backend mTLS is generally available for the following Application Load Balancers:
- Global external Application Load Balancers
- Regional external Application Load Balancers
- Cross-region internal Application Load Balancers
- Regional internal Application Load Balancers
The key benefits are as follows:
Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.
Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.
Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.
For more information, see Backend mTLS with managed workload identity overview
Cloud Scheduler is available in the following location:
asia-southeast3(Bangkok, Thailand)
Gemini Enterprise: Support for new actions (Public Preview)
Support for new actions is available in Public Preview for the following data stores:
- Microsoft OneDrive: Copy folder, move file, move folder, rename file, rename folder, share file or folder, and update file properties.
- Microsoft Outlook: Create calendar, RSVP to event, and update calendar.
- Microsoft SharePoint: Create list item, discard check out document, get list fields, get list item, list lists, share resource, update file properties, update list, update list item, and update page.
- Microsoft Teams: Add member to channel, create channel, create chat, create schedule, create time off entry, update channel, update channel message, update chat, update chat message, and update time off entry.
For more information, see Connect a third-party data source.
xAI's Grok 4.6 is generally available
Grok 4.6 is now generally available (GA) and available for production use on the global endpoint and the US multi-region endpoint.
Agent Platform SDK for Python version 2.0.1 is available
Version 2.0.1 of the Agent Platform SDK for Python (google-cloud-agentplatform) is now available. This release migrates generative AI modules to the Google Gen AI SDK, decouples the agent surface from google-cloud-aiplatform into a dedicated package, and introduces restructured namespaces.
For details and migration instructions from google-cloud-aiplatform, see the Agent Platform SDK for Python version 2.0.1 migration guide.
Google Cloud CCaaS 6.13
We've released version 6.13 of Google Cloud CCaaS.
The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.
This release addresses the following issues:
Fixed an issue where session metadata and data feed files were missing from external storage for chats that ended before the first message from the end-user.
Fixed an issue with Kustomer integrations where the caller's information didn't appear on the Incoming call page of the call adapter for direct-line inbound calls.
Fixed an issue with inbound mobile calls where the end-user leg of the call failed, returning
Unknown error, while the agent leg connected normally.Fixed an agent desktop issue where live call and chat data were lost.
Fixed an issue that occurred when the receiving agent in an agent-to-agent transfer didn't answer the call. The receiving agent was marked as active on the call indefinitely, even after the call ended.
Fixed an issue where the Dismiss button remained active after an agent sent a message, resulting in a 409 error when clicked.
Fixed an issue where duplicate "chat finished" events were reported when the end-user left a chat session at nearly the same time that the agent ended the chat session.
Fixed an issue where deflected calls were missing from the All Call History and Voice Inbound (IVR) History reports.
Fixed an issue that occurred when a direct inbound call was deflected to the agent's overcapacity queue, then that queue redirected to a SIP URI. The SIP redirect didn't include the custom SIP headers.
Fixed an issue where an in-queue announcement interval of several minutes for inbound IVR calls was incorrectly reduced to approximately 60 seconds.
Fixed an issue where calls that agents were unable to answer due to microphone failures were incorrectly reported as "picked up" in the Agent Activity Timeline report.
Fixed an issue where the system incorrectly marked agents as still being on a call after it ended, which either prevented them from changing their status to Available or silently blocked them from receiving new calls.
Fixed an issue where processing delays for ended calls caused timeout errors.
Fixed an issue where a sudden spike in calls bypassed capacity limits, causing agent availability to drop below required minimums.
Fixed an issue where the Agent Activity Timeline report incorrectly attributed manual agent logins and logouts to System instead of the appropriate agents.
Fixed an issue where calls with a missed offer became permanently stuck in the queue, preventing them from being routed to other available agents. This occurred with queues configured with multicast fallback disabled.
Fixed an issue where manual or cascade outbound calls that were canceled before connecting were missing from team-filtered Call History reports.
Fixed an issue that prevented over-capacity deflection from triggering when an agent warm-transferred an outbound call to a queue.
Fixed an issue where calls weren't correctly routed to the top-ranked agent when using agent priority overrides.
Fixed an issue where escalated voice calls were incorrectly reported as both answered and abandoned.
Fixed an issue where calls were missing from the All Call History and Voice Inbound History reports if the caller hung up before leaving a voicemail.
Fixed an issue where Salesforce click-to-dial outbound calls were incorrectly associated with the most recent open case instead of the case from which the call was initiated.
Fixed an issue where email accounts remained disconnected indefinitely after a temporary authentication failure.
Fixed an issue in Agent Assist where long periods of silence during calls caused connection timeouts, triggering false-positive error alerts.
Fixed an issue where the arrow-down-icon and arrow-up-icon arrows on the Agents > Filter Settings page were rendered at an incorrect scale.
Fixed an issue where incoming calls incorrectly created duplicate Salesforce accounts instead of linking to existing accounts.
Fixed an issue where the outbound call queue list displayed stale information, potentially causing calls to be placed in a queue that didn't match the agent's selected language.
Fixed an issue where the menus for transferring calls and forwarding calls to voicemail appeared in English instead of the agent's selected language.
Fixed an issue where the wrap-up disposition panel froze after a network reconnection even though the submission had completed successfully.
Fixed an issue where outbound, click-to-dial calls initiated in Salesforce incorrectly linked to and reassigned ownership of other cases associated with the same phone number.
Fixed an issue where the agent adapter went blank and prevented new calls from reaching the agent if an end-user hung up immediately after the agent received the call notification.
Fixed an issue where calls that failed to connect got stuck in a silent 'connecting' state in the call adapter.
Fixed an issue where Salesforce CRM connections dropped for organizations enforcing OAuth Refresh Token Rotation.
Fixed an issue where part of an agent's audio was dropped from recordings when a virtual task assistant ran in the middle of a call.
Fixed a web SDK issue where menus in the pre-chat and chat screens didn't comply with WAI-ARIA keyboard navigation standards.
Fixed a web SDK issue where screen readers couldn't identify the purpose of the Text size options for the chat screen.
Advanced reporting dashboards 6.4
We've released version 6.4 of the advanced reporting dashboards.
Real-time Agent Monitoring dashboard: new Active call ID(s) column
The Real-time Agent Monitoring dashboard now has an Active Call ID(s) column in the Live Agent Data table. The column displays the call ID(s) for any call in a connecting, connected, or reconnecting state for the agent. If an agent is handling multiple concurrent calls, the call IDs appear in a comma-separated list. The Active Call ID(s) column reduces the number of steps required for supervisors to identify active calls during live monitoring.
Improved filtering by team
We made the following changes to team-based filtering:
Renamed the Teams filter to Agent Teams to clarify that it filters by the agent team handling the interactions. This change is in the Real-time Queue Monitoring - Calls, Real-time Queue Monitoring - Chats, Real-time Connected - Calls, and Real-time Connected - Chats dashboards. For more information, see Queue monitoring dashboards, Real-time Connected - Calls dashboard, and Real-time Connected - Chats dashboard.
Added a Queue Teams filter to the Real-time Queued - Calls and Real-time Queued - Chats dashboards. This lets you filter queued interactions by the team assigned to the queue.
Improved the Real-time Calls and Real-time Chats dashboards
We made the following dashboard improvements:
Real-time Calls - Calls Connected dashboard. Added the following columns to the Connected Calls table:
Total Consumer Talk Time. Total time since the call first connected to a virtual agent or a human agent.
Total Hold Time. Total time the call has spent on hold so far, including a hold currently in progress.
Real-time Chats - Chats Connected dashboard. Added the following column to the Connected Chats table:
- Total Consumer Chat Time. Total time since the chat first connected to a virtual agent or a human agent.
Real-time Calls - Calls Queued dashboard: new Projecting column
The Real-time Calls - Calls Queued dashboard has a new Projecting column in the Call Queued table. Indicates whether the routing engine (deltacast) is currently projecting this queued call to an available agent.
Advanced reporting available in French Canadian
All advanced reporting dashboards and Explores are now available in French Canadian. When you select French Canadian as your profile language in the CCAI Platform portal, these dashboards and Explores display in that language.
Administrators: There's a new Français (CAN) option when you click Admin > Change Language in the CCAI Platform portal.
This release addresses the following issues:
Fixed an issue where the formatting of numeric values was inconsistent across tiles.
Fixed an issue where column headers, filter labels, and tile titles didn't immediately switch to a newly selected language.
Fixed an issue where the Productive Agents column in the tables of the Queue Group Performance - All dashboard didn't display values appropriate to the queue group settings.
Fixed an issue in the Call Queue Metrics (Historical) Explore where filtering by Agent Name without including it as a visible column resulted in zero rows being returned.
Fixed an issue that affected calls to a sub-menu that were deflected using Custom After Hours Deflection to a message. These calls were incorrectly attributed to the parent menu in the All Queued Interactions report.
Fixed the effectiveness of the Direction filter in the following dashboards:
Agent Performance. The Agent Productivity Detailed – Calls and Agent Productivity Detailed – Chats tables correctly reflect the filter setting.
Real-time Agent Monitoring. The Agent Performance table and historical metrics tiles correctly reflect the filter setting.
All Interactions – Calls and All Interactions – Chats. The IVR Interactions (calls only) and Virtual Agent Interactions tables correctly reflect the filter setting.
Fixed an issue with the Queue Performance - Calls dashboard when short abandons were present in the specified date range. The Avg Queue Time column in the Queue Summary table incorrectly displayed the raw sum of queue durations instead of a true average.
Fixed an issue where team filters didn't apply correctly when generating the Individual Call History Report and the Individual Chat History Report. This resulted in the inclusion of data from unmanaged queues.
Fixed an issue where French Canadian translations for several dashboard metrics and labels were incorrect, incomplete, or missing.
Fixed the following issues with the Real-time Calls - Calls Queued dashboard:
The Total Queued Now metric didn't include callers who were returned to the queue after an automated-answer detection miss.
The Current Max Queue Wait Time (H:M:S) and Current Avg Queue Wait Time (H:M:S) metrics mistakenly measured from a caller's original entry into the queue, rather than from their most recent return to the queue.
Fixed an issue where a gray bar appeared at the bottom of the advanced reporting dashboards, preventing a full view of the dashboards.
Resizable side panels in the Investigation Management experience
You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management experience in Google SecOps. You can adjust the panel width using your mouse or keyboard shortcuts to view detailed telemetry, parsed UDM records, and raw logs without navigating away from your main case queue.
To explore the complete triage workflow, see Investigation and case management overview.
The basic token-based authentication feature is generally available.
Filter version v4 is available and set as the default for the Latest alias.
Filter version v3 is promoted to the Stable alias in all supported regions
except the following:
- In
asia-northeast3,v1remains theStableversion. - In
australia-southeast2,v3becomes theStableversion on September 25, 2026.
If your templates use the Stable alias, they automatically upgrade to v3
when v3 becomes Stable in that region.
Filter versions v1 (except in asia-northeast3, and starting
September 25, 2026 in australia-southeast2) and v2 transition to Legacy
status and retire on December 17, 2026. If your templates are explicitly
configured with v1 or v2 in regions where those versions are in Legacy
status, you must migrate them to v3 or the Stable alias before December 17,
2026.
For more information, see Version release timeline and Model Armor filter version history.
September 17, 2026
Apigee hybridv1.16.10
On September 17, 2026 we released an updated version of the Apigee hybrid software, v1.16.10.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.16.10.
- For information on new installations, see The big picture.
Fixed in this release
| Bug ID | Description |
|---|---|
| 556750755 | Fixed an issue where EventFlow (Server-Sent Events) dropped or truncated events following a large (>16 KB) event under load on the http-adaptor datapath. |
| 547712217 | Fixed an issue where EventFlow (Server-Sent Events) responses larger than 16 KB could be truncated or corrupted across socket reads. |
| 519729209 | Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy. |
| 514384893 | Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses. |
| 505645076 | Fixed a security issue in the OAuthV2 policy to prevent unauthorized token injection via HTTP form parameters. |
| 505543289 | Fixed thread-safety issues in the Netty client connection pool and channel lifecycle. |
| 503817773 | Improved security in the OAuthV2 policy implicit grant redirect_uri validation. |
| 502268966 | Apigee hybrid now supports optional decoding of percent-encoded path separators (%2F and %5C) before flow selection via the request.path.decode.encoded.separators proxy property. |
| 480770263 | Fixed an issue in the SpikeArrest policy to handle edge cases that previously caused NullPointerException and 500 errors. |
| 472526232 | Improved SAML assertion validation in the ValidateSAMLAssertion policy against entity and comment injection. |
| 470375542 | Fixed a memory leak in WSFrameDecoder that could result in a spike in 503 responses with no_healthy_upstream errors. |
| 449228485 | Apigee hybrid now supports configuring custom Kubernetes PodDisruptionBudget (minAvailable or maxUnavailable) values for Apigee hybrid components in your overrides.yaml file. |
| 402250928 | Apigee hybrid now supports routing outbound calls from AI policies, such as the Model Armor and semantic caching policies, through an HTTP forward proxy. |
Kubernetes 1.36 support
Apigee hybrid v1.16.10 adds support for Kubernetes 1.36 on Google Kubernetes Engine (GKE), Google Distributed Cloud Virtual for VMware (vSphere), Google Distributed Cloud Virtual for bare metal, Amazon EKS, Azure AKS, and Rancher Kubernetes Engine (RKE2).
For more information, see Supported platforms.
Forward proxy support for AI policies
Apigee hybrid v1.16.10 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy.
For more information, see Configure a forward proxy, Get started with the Model Armor policies, and Get started with semantic caching policies.
| Bug ID | Description |
|---|---|
| N/A | Security fixes for apigee-asm-ingress. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-asm-istiod. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerabilities:
|
| N/A | Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-mart-server. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-operators. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-prometheus-adapter. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-runtime. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-synchronizer. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-watcher. This addresses the following vulnerabilities: |
You can add unit tests to pipelines to validate your SQL transformation logic against mock datasets. Unit tests for pipelines are generally available (GA).
The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.
- Cloud TPU API
tpu.googleapis.com/QueuedResource
Cloud SQL for MySQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.
For more information, see Use advanced disaster recovery (DR).
Cloud SQL for PostgreSQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.
For more information, see Use advanced disaster recovery (DR).
Generally available: The storage-optimized Z4D machine series is generally available for Compute Engine. Powered by AMD EPYC Turin processors and Titanium offload processors, Z4D instances are purpose-built for low core usage and high storage density workloads such as:
- SQL, NoSQL, and vector databases
- Data analytics and data warehouses
- Search
- Parallel file systems for AI/ML
The Z4D machine series delivers up to 3 TB of memory and 42,000 GiB of local Titanium SSD capacity. Z4D also supports up to 400 Gbps of network bandwidth using two physical NICs. Z4D instances are available in predefined standardlssd and highlssd machine shapes.
For more information, see Storage-optimized machine family.
cos-beta-133-19999-44-44
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.18.48 | v29.4.3 | v2.3.4 | See List |
cos-129-19506-448-36
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.105 | v27.5.1 | v2.2.7 | See List |
Fixed CVE-2026-56391 in sys-apps/coreutils.
Fixed CVE-2026-56391 in sys-apps/coreutils.
Fixed CVE-2026-58470 in net-misc/wget.
Fixed CVE-2026-80590 in the Linux kernel.
Fixed CVE-2026-59890 in dev-python/setuptools.
Fixed CVE-2026-80737 in the Linux kernel.
Upgraded net-libs/nghttp2 to 1.69.0 and fixed CVE-2026-58055.
Fixed CVE-2026-80788 in the Linux kernel.
Fixed CVE-2026-80789 in the Linux kernel.
Fixed CVE-2026-80791 in the Linux kernel.
Fixed CVE-2026-80792 in the Linux kernel.
Fixed CVE-2026-80793 in the Linux kernel.
Fixed CVE-2026-80805 in the Linux kernel.
Fixed CVE-2026-80806 in the Linux kernel.
Fixed CVE-2026-80808 in the Linux kernel.
Fixed CVE-2026-80837 in the Linux kernel.
Fixed CVE-2026-80838 in the Linux kernel.
Fixed CVE-2026-80839 in the Linux kernel.
Fixed CVE-2026-80842 in the Linux kernel.
Fixed CVE-2026-80843 in the Linux kernel.
Fixed CVE-2026-80845 in the Linux kernel.
Fixed CVE-2026-80852 in the Linux kernel.
Fixed CVE-2026-80854 in the Linux kernel.
Fixed CVE-2026-80855 in the Linux kernel.
Fixed CVE-2026-80856 in the Linux kernel.
Fixed CVE-2026-80862 in the Linux kernel.
Fixed CVE-2026-80916 in the Linux kernel.
Fixed CVE-2026-80917 in the Linux kernel.
cos-125-19216-655-28
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.105 | v27.5.1 | v2.2.7 | See List |
Fixed a performance issue in the GVE driver on multi-NUMA systems.
Upgraded net-libs/libnftnl to v1.2.9.
Fixed CVE-2026-80590 in the Linux kernel.
Fixed CVE-2026-80737 in the Linux kernel.
Fixed CVE-2026-80788 in the Linux kernel.
Fixed CVE-2026-80789 in the Linux kernel.
Fixed CVE-2026-80791 in the Linux kernel.
Fixed CVE-2026-80792 in the Linux kernel.
Fixed CVE-2026-80793 in the Linux kernel.
Fixed CVE-2026-80805 in the Linux kernel.
Fixed CVE-2026-80806 in the Linux kernel.
Fixed CVE-2026-80808 in the Linux kernel.
Fixed CVE-2026-80837 in the Linux kernel.
Fixed CVE-2026-80838 in the Linux kernel.
Fixed CVE-2026-80839 in the Linux kernel.
Fixed CVE-2026-80842 in the Linux kernel.
Fixed CVE-2026-80843 in the Linux kernel.
Fixed CVE-2026-80845 in the Linux kernel.
Fixed CVE-2026-80852 in the Linux kernel.
Fixed CVE-2026-80854 in the Linux kernel.
Fixed CVE-2026-80855 in the Linux kernel.
Fixed CVE-2026-80856 in the Linux kernel.
Fixed CVE-2026-80862 in the Linux kernel.
Fixed CVE-2026-80916 in the Linux kernel.
Fixed CVE-2026-80917 in the Linux kernel.
Runtime sysctl changes:
- Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068
cos-117-18613-731-21
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.153 | v24.0.9 | v1.7.34 | See List |
Fixed CVE-2026-80590 in the Linux kernel.
Fixed CVE-2026-80737 in the Linux kernel.
Fixed CVE-2026-80788 in the Linux kernel.
Fixed CVE-2026-80789 in the Linux kernel.
Fixed CVE-2026-80791 in the Linux kernel.
Fixed CVE-2026-80792 in the Linux kernel.
Fixed CVE-2026-80793 in the Linux kernel.
Fixed CVE-2026-80805 in the Linux kernel.
Fixed CVE-2026-80806 in the Linux kernel.
Fixed CVE-2026-80808 in the Linux kernel.
Fixed CVE-2026-80842 in the Linux kernel.
Fixed CVE-2026-80843 in the Linux kernel.
Fixed CVE-2026-80852 in the Linux kernel.
Fixed CVE-2026-80854 in the Linux kernel.
Fixed CVE-2026-80855 in the Linux kernel.
Fixed CVE-2026-80856 in the Linux kernel.
Fixed CVE-2026-80916 in the Linux kernel.
Fixed CVE-2026-80917 in the Linux kernel.
cos-121-18867-584-23
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.153 | v27.5.1 | v2.0.10 | See List |
Fixed CVE-2026-80590 in the Linux kernel.
Fixed CVE-2026-80737 in the Linux kernel.
Fixed CVE-2026-80788 in the Linux kernel.
Fixed CVE-2026-80789 in the Linux kernel.
Fixed CVE-2026-80791 in the Linux kernel.
Fixed CVE-2026-80792 in the Linux kernel.
Fixed CVE-2026-80793 in the Linux kernel.
Fixed CVE-2026-80805 in the Linux kernel.
Fixed CVE-2026-80806 in the Linux kernel.
Fixed CVE-2026-80808 in the Linux kernel.
Fixed CVE-2026-80842 in the Linux kernel.
Fixed CVE-2026-80843 in the Linux kernel.
Fixed CVE-2026-80852 in the Linux kernel.
Fixed CVE-2026-80854 in the Linux kernel.
Fixed CVE-2026-80855 in the Linux kernel.
Fixed CVE-2026-80856 in the Linux kernel.
Fixed CVE-2026-80917 in the Linux kernel.
You can use unit tests to test Dataform actions against mock data with an expected result set. Dataform unit tests are generally available (GA).