Boletines de Vulnerabilidades

CVE-2026-2264

   
Software afectado GOOGLE
 
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.

For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-2264