OpenStack 2026.2 Hibiscus Has Launched

The updated cloud platform integrates hardware-backed memory encryption and enhanced DNS security features.

Updated on Sept. 30, 2026 in Data Centers

Isometric editorial illustration of modular server chassis components in a clean, structured arrangement, representing cloud computing infrastructure.
The OpenInfra Foundation has released OpenStack 2026.2, introducing hardware-backed memory encryption and advanced DNS security to support evolving AI-heavy infrastructure requirements. AI Illustration. Upload story photo >

Live Poll

Do you trust open-source cloud infrastructure to secure your company's most sensitive digital data?

The OpenInfra Foundation released OpenStack 2026.2, code-named Hibiscus, on September 30, 2026. This version of the open-source cloud software adds support for hardware-backed memory encryption and new DNS security capabilities.

Why it matters

The platform update prioritizes security hardening in response to a recent increase in reported vulnerabilities. These enhancements also address the evolving requirements of AI-heavy infrastructure by improving hardware and storage management.

The release cycle saw 600 contributors deliver 11,500 code changes, marking a 21% increase in participant volume. The project recorded 42 security advisories during the first eight months of 2026, a sharp rise from the previous five-year average of 3.2 advisories per year.

The players

OpenInfra Foundation

The nonprofit organization that governs the development and release of the open-source OpenStack cloud computing platform.

Nova

The primary compute provisioning component of the OpenStack stack responsible for managing virtual machine instances.

Neutron

The OpenStack project component that handles networking-as-a-service and connectivity between virtual instances.

Designate

The OpenStack service that provides DNS-as-a-service to manage domain records within the cloud environment.

The details

The Nova compute service now implements hardware-backed memory encryption for virtual machines by utilizing the hw:mem_encryption_model setting, with newly added support for AMD SEV-SNP and Intel TDX architectures. For network security, the Designate project added DANE support through TLSA record storage and split-horizon DNS via a BIND9 backend. Additionally, the Neutron networking component now uses an EVPN service plugin to broadcast tenant network prefixes directly into the data center fabric.

Timeline

  1. First eight months of 2026: The project recorded 42 security advisories.

  2. September 30, 2026: OpenStack 2026.2 Hibiscus reached general availability.

The Tech Race

The transition to hardware-backed memory encryption places OpenStack in closer alignment with commercial secure-cloud offerings. This release follows a pattern of hardening open-source infrastructure to address vulnerabilities that could otherwise allow for cross-tenant data access.

Operators can now manage virtual GPU resources via the Cyborg accelerator project and enable memory encryption for sensitive workloads. Organizations managing multi-tenant environments should review these updates to patch existing zone ownership bypass concerns.

The takeaway

The Hibiscus release signals a pivot toward stronger hardware-level security as standard practice for cloud deployments. Developers should monitor future project updates for details on upcoming AI agent support cycles.

Further reading

For more on evolving infrastructure requirements, visit Data Centers.

Live Poll

Do you trust open-source cloud infrastructure to secure your company's most sensitive digital data?