AWS Security Bulletin Report

Showing latest from S3: _latest-report-details.md

AWS Security Bulletins Report

Severe/Critical Security Bulletins in the Last 7 Days

Ongoing updates on Copy.fail and variants

CVE-2026-8596 & CVE-2026-8597 - Model artifact integrity verification issues in Amazon SageMaker Python SDK

CVE-2026-8838 - Remote Code Execution in amazon-redshift-python-driver

CVE-2026-9133 - Arbitrary file read in rabbitmq-aws plugin

CVE-2026-8178 - Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

CVE-2026-8686 - Heap out-of-bounds read in coreMQTT MQTT5 property parsing

CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

CVE-2026-7191 - Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS

CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python

CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport

CVE-2026-5429 - Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme

CVE-2026-4428: Issues with AWS-LC - CRL Distribution Point Scope Check Logic Error

CVE-2026-4270 - AWS API MCP File Access Restriction Bypass

CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit