// Alert

Google Cloud threat report

Google Cloud Looker released version 26.12 to patch CVE-2026-15810, a cross-site scripting vulnerability allowing attackers to hijack administrator accounts through malicious URLs. Cloud-hosted instances were automatically remediated; self-hosted operators must apply patches to supported release branches. The release also enforces multi-factor authentication by default for email/password authentication.

// Get alerts for Google Cloud