# Crossplane v2.2.6

> Orchestration & Management · 2026-09-15

A security-focused maintenance release with updates to the Go toolchain and dependencies for upstream CV fixes. Package-revision handoffs are also corrected so incoming revisions can take control of established objects without manual intervention.

## Action needed
- **[security · high]** The `google.golang.org/grpc` update for `GHSA-2v4p-qf9q-27wj`
  - `google.golang.org/grpc` is updated to `v1.83.2` to pick up upstream CVE fixes, including advisory `GHSA-2v4p-qf9q-27wj`. The updated dependency ships in this release.
- **[security]** The Go toolchain security update
  - The Go toolchain is updated to `1.26.7` to pick up upstream CVE fixes. The lock file is also refreshed.
- **[security]** The `golang.org/x/crypto` security update
  - `golang.org/x/crypto` is updated to `v0.56.0` to pick up upstream CVE fixes. The updated dependency ships in this release.

## Other recorded changes
- 1 (defect_corrected 1)

[Full analysis](https://ratatosk.io/en/releases/crossplane/v2.2.6)

[Original release notes](https://github.com/crossplane/crossplane/releases/tag/v2.2.6)
