CVE-2026-2264EPSS p27.5%
CVE-2026-2264CVE-2026-2264
Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.
For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Scoring
| EPSS | 0.36% probability of exploitation · percentile 27.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-24 |