Amazon Web Services

aws.amazon.com

Imported from official source

Cloud provider; publisher of security bulletins.

Type
Company
Scope
US · global
Website
aws.amazon.com
Feed
Atom

Publications 65

  1. CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

    Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface d...

    Security notice Cybersecurity
  2. CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

    Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based ti...

    Security notice Cybersecurity
  3. CVE-2026-11400 and CVE-2026-11401

    Security notice Cybersecurity
  4. CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

    Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLam...

    Security notice Cybersecurity
  5. CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python

    Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open s...

    Security notice Cybersecurity 2 versions
  6. CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

    Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We...

    Security notice Cybersecurity 2 versions
  7. CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

    Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open sourc...

    Security notice Cybersecurity
  8. CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

    Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it...

    Security notice Cybersecurity 2 versions
  9. CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

    Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS...

    Security notice Cybersecurity
  10. CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

    Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that...

    Security notice Cybersecurity
  11. CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection

    Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing ...

    Security notice Cybersecurity
  12. CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

    Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs ...

    Security notice Cybersecurity 2 versions
  13. CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library

    Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic J...

    Security notice Cybersecurity 2 versions
  14. CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport

    Security notice Cybersecurity 4 versions Source page stopped responding
  15. CVE-2026-8178 - Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

    Security notice Cybersecurity 5 versions Source page stopped responding
  16. Issues with Amazon Athena ODBC Driver

    Security notice Cybersecurity 6 versions Source page stopped responding
  17. Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow

    Security notice Cybersecurity 5 versions Source page stopped responding
  18. CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server

    Bulletin ID: 2026-076-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 13:00 PM PDT Description: Amazon DocumentDB MCP Server is an open-source Model Context...

    Security notice Cybersecurity
  19. CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK

    Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline ...

    Security notice Cybersecurity
  20. CVE-2026-87911

    Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

    Security notice Cybersecurity
  21. CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch

    Bulletin ID: 2026-098-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:30 AM PDT Description: log4j-cve-2021-44228-hotpatch is a tool which injects a Java...

    Security notice Cybersecurity
  22. CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin

    Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder ...

    Security notice Cybersecurity
  23. CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools

    Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents....

    Security notice Cybersecurity
  24. CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server

    Bulletin ID: 2026-105-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 08:30 AM PDT Description: AWS Security Agent is a managed AWS service that provides AI...

    Security notice Cybersecurity
  25. CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination

    Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We...

    Security notice Cybersecurity
  26. CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

    Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it...

    Security notice Cybersecurity
  27. CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server

    Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-serv...

    Security notice Cybersecurity
  28. CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector

    Bulletin ID: 2026-084-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:00 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...

    Security notice Cybersecurity
  29. CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

    Bulletin ID: 2026-097-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:00 AM PDT Description: Amazon awslabs.dynamodb-mcp-server is an open-source Model C...

    Security notice Cybersecurity
  30. CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

    Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to ma...

    Security notice Cybersecurity
  31. CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java

    Bulletin ID: 2026-100-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...

    Security notice Cybersecurity 2 versions
  32. CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool

    Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and...

    Security notice Cybersecurity 2 versions
  33. CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

    Bulletin ID: 2026-102-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/08/2026 12:30 PM PDT Description: A stored cross-site scripting (XSS) issue in the Vega expres...

    Security notice Cybersecurity 2 versions
  34. CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

    Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and m...

    Security notice Cybersecurity 2 versions
  35. CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector

    Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service tha...

    Security notice Cybersecurity 2 versions

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.