aws Latest High & Critical Vulnerabilities
Latest High & Critical vulnerabilities published by aws
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Local Code Execution Vulnerability in AWS FPGA Development Kit
CVE-2026-85028AwsAws-fpga7.3HIGHCommand Injection Vulnerability in AWS Codecatalyst-Blueprints Framework
CVE-2026-85012Aws@amazon-codecatalyst/b...8.5HIGHCleartext Storage Vulnerability in Amazon SageMaker Python SDK
CVE-2026-83551AwsSagemaker-python-sdk8.5HIGHNeptune Connector Vulnerability in AWS Athena Federated Query
CVE-2026-77810AwsAthena Federated Query...9.4CRITICALPrototype Pollution in Time Series Visual Builder Plugin for OpenSearch Dashboards
CVE-2026-18420AwsAmazon Opensearch Service8.7HIGHIncorrect Privilege Assignment in Amazon Athena Federated Query Connector
CVE-2026-75910AwsAthena Federated Query...7.1HIGHSQL Query Validation Bypass Vulnerability in OpenSearch SQL Plugin by Amazon
CVE-2026-18428AwsOpensearch8.7HIGHInput Validation Issue in OpenSearch Security Analytics Plugin
CVE-2026-18952AwsOpensearch8.6HIGHMissing Authorization in Amazon OpenSearch Alerting Plugin
CVE-2026-19311AwsOpensearch8.6HIGHInsecure Direct Object Reference in Amazon Strands Agents Tools
CVE-2026-19111AwsStrands-agents-tools8.6HIGHInput Validation Flaw in Amazon Bedrock AgentCore by AWS
CVE-2026-18830AwsAmazon Bedrock Agentco...πΎπ‘8.6HIGHPrompt Injection Vulnerability in Amazon Strands Agents Tools
CVE-2026-18733AwsStrands-agents-tools7.5HIGHImproper Endpoint Restriction in Amazon MQ MCP Server by AWS Labs
CVE-2026-18655AwsAmazon-MQ-mcp-server7.1HIGHUncontrolled Recursion Vulnerability in AWS Smithy JSON Runtime Crate
CVE-2026-18140AwsAws-smithy-json8.7HIGHImproper Neutralization Vulnerability in AWS Bedrock AgentCore Python SDK
CVE-2026-16796AwsBedrock-agentcore 1.18.18.4HIGHDenial of Service Vulnerability in Amazon AWS Smithy HTTP Server
CVE-2026-16756AwsAws-smithy-http-server8.7HIGHInitialization Failure in AWS API MCP Server Allows Bypassing Security Policies
CVE-2026-16584AwsAws-api-mcp-server7.3HIGHMissing Validation in s2n-tls Affects TLS 1.3 Connections
CVE-2026-16317AwsS2n-tls8.3HIGHUncontrolled Recursion Vulnerability in Smithy-RS Framework Affecting AWS SDK for Rust
CVE-2026-15957AwsAws-sdk-rust8.7HIGHOS Command Injection Vulnerability in AWS jsii-diff Package
CVE-2026-15895AwsJsii8.4HIGHServer-Side Request Forgery in AWS HealthLake MCP Server by AWS
CVE-2026-15643AwsAwslabs.healthlake-mcp...9.2CRITICALImproper Link Resolution in AWS Research and Engineering Studio
CVE-2026-14904AwsRes7.1HIGHSQL Injection Vulnerability in Amazon mcp-gateway-registry
CVE-2026-14471AwsMcp Gateway & Registry8.6HIGHDeserialization Vulnerability in AWS Advanced JDBC Wrapper by Amazon
CVE-2026-14265AwsAws Advanced Jdbc Wrapper7.7HIGHOS Command Injection in AWS CDK Library Impacting Node.js Functions
CVE-2026-13760AwsAws Cdk7HIGH