Apigee X
60 updates from Google Cloud.
Security: CVE-2026-42151CVE-2026-42154CVE-2026-44903CVE-2026-40179
<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42151">CVE-2026-42151</a><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42154">CVE-2026-42154</a><a…
On September 21st, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On September 21st, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
Fixed: Addendum to Apigee release notes dated August 27, 2026 (1-18-0-apigee-4).
Addendum to Apigee release notes dated <a href="#August_27_2026">August 27, 2026</a> (1-18-0-apigee-4).
SemanticCacheLookup policy supports non-default Vector Search distance measures
SemanticCacheLookup policy supports non-default Vector Search distance measures Available in Apigee 1-18-0-apigee-4 and later. A new optional <DistanceMeasureType> element accepts…
On August 13th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On August 13th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
On July 16th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On July 16th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
Security: An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on...
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allowed an authenticated attacker to exfiltrate cross-tenant…
Support for payload operations matching in API Products
Support for payload operations matching in API Products Apigee now supports payload operations matching (payloadOperationGroup) in API Products, powered by the new ParsePayload policy. Payload…
Security: Apigee Emulator
Apigee Emulator This release addresses 10 security vulnerabilities in the Netty networking library and the embedded Go standard library. All Netty fixes come from upgrading to 4.1.135.Final; all Go…
Apigee Emulator v2.0.1: On June 24, 2026, we released Apigee Emulator version 2.0.1.
On June 24, 2026, we released Apigee Emulator version 2.0.1. This is a security-only hotfix release on top of v2.0.0 that addresses 10 security vulnerabilities in the Netty networking library and…
Apigee Emulator
Apigee Emulator • Upgraded Netty to 4.1.135.Final (from 4.1.133.Final) and pinned all transitive netty-* artifacts via netty-bom. • Refreshed the Cassandra base image to pick up Go standard library…
Security: CVE-2026-27143CVE-2019-14993CVE-2021-39155CVE-2021-39156CVE-2022-23635CVE-2026-27140CVE-2026-27144CV...
<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14993">CVE-2019-14993</a><a…
On June 18th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On June 18th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
Security: This addresses the following...
This addresses the following vulnerabilities:<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39820">CVE-2026-39820</a><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499">CVE-2026-42499</a><a…
Apigee EventFlow now supports the DataCapture policy
Apigee EventFlow now supports the DataCapture policy You can now use the DataCapture policy within an EventFlow to extract and persist data from server-sent events (SSE) streams, such as token…
Manage Spaces in the Apigee UI
Manage Spaces in the Apigee UI You can now create, view, update, and delete spaces, and manage their Identity and Access Management (IAM) policies directly in the Apigee UI. Previously, these…
Apigee Emulator v2.0.0: On May 22, 2026, we released Apigee Emulator version 2.0.0.
On May 22, 2026, we released Apigee Emulator version 2.0.0. Starting with this release, the Apigee Emulator is versioned and released independently from Apigee hybrid. This enables faster delivery…
Apigee Emulator
Apigee Emulator • The Apigee Emulator now follows independent semantic versioning (MAJOR.MINOR.PATCH), decoupled from Apigee hybrid versioning. • Updated base Cassandra image to version 4.0.19. •…
Security: Apigee Emulator
Apigee Emulator This release addresses 78 security vulnerabilities across Cassandra base image, Go standard library, Java dependencies, and Python packages. Key fixes include: And 68 additional…
Security: On May 20, 2026, we published a security bulletin for Apigee.
On May 20, 2026, we published a security bulletin for Apigee. A vulnerability was found in Apigee (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2264">CVE-2026-2264</a>) where the…
Security: On May 12th, 2026, we released an updated version of Apigee (1-17-0-apigee-7).
On May 12th, 2026, we released an updated version of Apigee (1-17-0-apigee-7).
Security: This addresses the following vulnerabilities: ...
This addresses the following vulnerabilities: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42587">CVE-2026-42587</a><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5588">CVE-2026-5588</a><a…
On April 29th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On April 29th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
Relaxed limitation on header name for Client IP resolution
Relaxed limitation on header name for Client IP resolution The client IP can now be resolved from any header, not just the X-Forwarded-For header. The most common headers are X-Forwarded-For or…
Fixed: Correction to April 2, 2026 release note: Deployment disruption for Apigee Drupal Portal via Google Cloud Marketplace
Correction to <a href="#April_02_2026">April 2, 2026 release note: Deployment disruption for Apigee Drupal Portal via Google Cloud Marketplace</a> For the deployment disruption announced on April 2,…
On April 6th, 2026, we released an updated version of Apigee.
On April 6th, 2026, we released an updated version of Apigee. This change introduces the new apigee.coreServiceAgent IAM role for Apigee. Effective immediately, use apigee.coreServiceAgent instead…
Breaking: Deployment disruption for Apigee Drupal Portal via Google Cloud Marketplace
Deployment disruption for Apigee Drupal Portal via Google Cloud Marketplace Google Cloud Deployment Manager was deprecated as of March 31, 2026. We are currently transitioning the Apigee Drupal…
General Availability (GA) launch of Model Context Protocol (MCP) in Apigee
General Availability (GA) launch of Model Context Protocol (MCP) in Apigee With this release, Model Context Protocol (MCP) in Apigee is <a…
Enhanced OAS server URL path handling for MCP in Apigee
Enhanced OAS server URL path handling for MCP in Apigee With this feature enhancement, your OpenAPI specification (OAS) configurations behave exactly as defined in the OAS standard, automatically…
Issue: Known Issue 496552286: Deployment fails for MCP Discovery Proxies in regions with capacity limitations.
Known Issue 496552286: Deployment fails for MCP Discovery Proxies in regions with capacity limitations. For more information, see <a…
Updated MCP server target endpoint for MCP Discovery Proxies
Updated MCP server target endpoint for MCP Discovery Proxies With the GA launch of Model Context Protocol (MCP) in Apigee, the structure of the MCP server target endpoint for MCP Discover Proxies…
Security: This addresses the following vulnerabilities: CVE-2026-33210CVE-2026-25679CVE-2026-27139CVE-2026-271422026-33186
This addresses the following vulnerabilities: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33210">CVE-2026-33210</a><a…
On March 19th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
On March 19th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for…
Security: This addresses the following vulnerabilities: ...
This addresses the following vulnerabilities: <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a><a…
Security: This addresses the following vulnerabilities: CVE-2025-61730CVE-2025-68156CVE-2025-54388CVE-2025-61727CVE-2025-61729
This addresses the following vulnerabilities: <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61730">CVE-2025-61730</a><a…
Security: A vulnerability was identified in the Apigee platform (CVE-2025-13292) that could have allowed a malicious actor with...
A vulnerability was identified in the Apigee platform (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13292">CVE-2025-13292</a>) that could have allowed a malicious actor with…
Security: This addresses the following vulnerabilities: CVE-2025-61730CVE-2025-68156CVE-2025-54388CVE-2025-61727CVE-2025-61729
This addresses the following vulnerabilities: CVE-2025-61730CVE-2025-68156CVE-2025-54388CVE-2025-61727CVE-2025-61729
This addresses the following...
This addresses the following vulnerabilities:CVE-2025-58187CVE-2025-61723CVE-2025-61725CVE-2025-61729CVE-2025-61727