CVE-2026-92943Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python Exploitation status Not known exploited Fix YesAffected product A AWSIoTPythonSDK Published 09/17/2026 Severity Critical CVE-2026-86831Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Exploitation status Not known exploited Fix YesAffected product A aws-network-policy-agent Published 09/16/2026 Severity High CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center Exploitation status Not known exploited Fix YesAffected product I iam-identity-center-team Published 09/14/2026 Severity High CVE-2026-89332Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration Exploitation status Not known exploited Fix YesAffected product K Kiro IDE Published 09/11/2026 Severity Medium CVE-2026-89090Denial of service in the event stream header decoder in AWS SDK for Go v2 Exploitation status Not known exploited Fix YesAffected product A AWS SDK for Go v2 Published 09/11/2026 Severity High CVE-2026-18061Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin Exploitation status Not known exploited Fix YesAffected product A AWS Advanced JDBC Wrapper Published 09/11/2026 Severity Medium CVE-2026-89066OS command injection in the task synthesis component in projen Exploitation status Not known exploited Fix YesAffected product P projen Published 09/11/2026 Severity High CVE-2026-89065Relative path traversal in the generated file manifest cleanup component in projen Exploitation status Not known exploited Fix YesAffected product P projen Published 09/11/2026 Severity Medium CVE-2026-89049Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent Exploitation status Not known exploited Fix YesAffected product A Amazon SSM Agent Published 09/10/2026 Severity High CVE-2026-87913Missing S3 bucket ownership verification in the AWS Security Agent MCP server Exploitation status Not known exploited Fix YesAffected product A AWS Security Agent MCP server Published 09/10/2026 Severity Medium CVE-2026-87912Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops Exploitation status Not known exploited Fix YesAffected product A AWS Security Agent plugin Published 09/10/2026 Severity Medium CVE-2026-87911Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server Exploitation status Not known exploited Fix YesAffected product A AWS Labs postgres MCP Server Published 09/09/2026 Severity Critical CVE-2026-85788Incomplete list of disallowed inputs in awslabs mysql-mcp-server Exploitation status Not known exploited Fix YesAffected product A AWS Labs MySQL MCP Server Published 09/09/2026 Severity Medium CVE-2026-84942Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards Exploitation status Not known exploited Fix YesAffected product O OpenSearch Dashboards Published 09/08/2026 Severity Medium CVE-2026-85781Unverified access point ownership in Amazon EFS CSI Driver Exploitation status Not known exploited Fix YesAffected product A aws-efs-csi-driver Published 09/04/2026 Severity Medium CVE-2026-85028Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit Exploitation status Not known exploited Fix YesAffected product A aws-fpga Published 09/03/2026 Severity High CVE-2026-85012OS command injection in the Amazon CodeCatalyst blueprints SDK Exploitation status Not known exploited Fix YesAffected product @ @amazon-codecatalyst/blueprints.blueprint Published 09/03/2026 Severity High CVE-2026-83551Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path Exploitation status Not known exploited Fix YesAffected product S sagemaker-python-sdk Published 09/01/2026 Severity High CVE-2026-81838Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac) Exploitation status Not known exploited Fix YesAffected product D diagram-as-code Published 08/27/2026 Severity Medium CVE-2026-77811Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards Exploitation status Not known exploited Fix YesAffected product O OpenSearch Dashboards dashboards-observability plugin Published 08/21/2026 Severity Medium CVE-2026-77810Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector Exploitation status Not known exploited Fix YesAffected product A Athena Federated Query Neptune Connector Published 08/21/2026 Severity Critical CVE-2026-18420RCE via Prototype Pollution in OpenSearch Dashboards Exploitation status Not known exploited Fix YesAffected product A Amazon OpenSearch Service Published 08/20/2026 Severity High CVE-2026-75910Incorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment template Exploitation status Not known exploited Fix YesAffected product A Athena Federated Query Clickhouse Connector deployment template Published 08/20/2026 Severity High CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards Exploitation status Not known exploited Fix YesAffected product A Amazon OpenSearch Service Published 08/18/2026 Severity High CVE-2026-18428SQL Query Validation Bypass in OpenSearch Direct Query Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/13/2026 Severity High CVE-2026-19643Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms Exploitation status Not known exploited Fix YesAffected product A aws-sdk-cpp Published 08/12/2026 Severity Medium CVE-2026-19642Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp Exploitation status Not known exploited Fix YesAffected product A aws-sdk-cpp Published 08/12/2026 Severity Medium CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/12/2026 Severity High CVE-2026-19311Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin Exploitation status Not known exploited Fix YesAffected product O OpenSearch Published 08/12/2026 Severity High CVE-2026-19111Insecure direct object reference in Strands Agents Tools memory tool namespace isolation Exploitation status Not known exploited Fix YesAffected product S strands-agents-tools Published 08/06/2026 Severity High CVE-2026-18954Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server Exploitation status Not known exploited Fix YesAffected product D documentdb-mcp-server Published 08/05/2026 Severity Medium CVE-2026-18953Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server Exploitation status Not known exploited Fix YesAffected product A aws-transform-mcp-server Published 08/05/2026 Severity Medium CVE-2026-18830Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API Exploitation status Not known exploited Fix Not confirmed Affected product A Amazon Bedrock AgentCore harness Published 08/04/2026 Severity High CVE-2026-18733Prompt injection bypasses shell tool consent gate in Strands Agents Tools Exploitation status Not known exploited Fix YesAffected product S strands-agents-tools Published 08/03/2026 Severity High CVE-2026-18654Disabled SSH host key verification in Amazon AWS CLI EMR helper commands Exploitation status Not known exploited Fix YesAffected product A aws-cli Published 08/03/2026 Severity Medium CVE-2026-18655Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection Exploitation status Not known exploited Fix YesAffected product A amazon-mq-mcp-server Published 08/03/2026 Severity High CVE-2026-18394Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration Exploitation status Not known exploited Fix YesAffected product S Strands Agents Tools Published 07/31/2026 Severity Medium CVE-2026-18481Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft Exploitation status Not known exploited Fix YesAffected product A AWS Ops Wheel Published 07/31/2026 Severity Medium CVE-2026-18140Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers Exploitation status Not known exploited Fix YesAffected product A aws-smithy-json Published 07/30/2026 Severity High CVE-2026-18245Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react Exploitation status Not known exploited Fix YesAffected product A Amplify Codegen UI Published 07/30/2026 Severity Medium CVE-2026-16796Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() Exploitation status Not known exploited Fix YesAffected product B bedrock-agentcore 1.18.1 Published 07/23/2026 Severity High CVE-2026-16756Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service Exploitation status Not known exploited Fix YesAffected product A aws-smithy-http-server Published 07/23/2026 Severity High CVE-2026-16584AWS API MCP Server Security Policy Bypass via Startup Failure Exploitation status Not known exploited Fix YesAffected product A aws-api-mcp-server Published 07/23/2026 Severity High CVE-2026-16317Silent Drop of TLS 1.3 Encrypted Records in s2n-tls Exploitation status Not known exploited Fix YesAffected product S s2n-tls Published 07/21/2026 Severity High CVE-2026-15957Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes Exploitation status Not known exploited Fix YesAffected product A aws-sdk-rust Published 07/21/2026 Severity High CVE-2026-15415Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server Exploitation status Not known exploited Fix YesAffected product A aws-healthomics-mcp-server Published 07/17/2026 Severity Medium CVE-2026-12283SQL injection in Amazon Athena Synapse connector Exploitation status Not known exploited Fix YesAffected product A aws-athena-query-federation Published 07/17/2026 Severity Medium CVE-2026-15737Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK Exploitation status Not known exploited Fix YesAffected product B bedrock-agentcore Published 07/16/2026 Severity Medium CVE-2026-15895OS command injection in jsii-diff in AWS jsii Exploitation status Not known exploited Fix YesAffected product J jsii Published 07/15/2026 Severity High CVE-2026-15643AWS HealthLake MCP Server SSRF via Pagination URL Exploitation status Not known exploited Fix YesAffected product A awslabs.healthlake-mcp-server Published 07/14/2026 Severity Critical CVE-2026-14904RES Auth.GetUserPrivateKey Arbitrary File Read Exploitation status Not known exploited Fix YesAffected product R res Published 07/07/2026 Severity High CVE-2026-14471Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry Exploitation status Not known exploited Fix YesAffected product M MCP Gateway & Registry Published 07/06/2026 Severity High CVE-2026-14265RCE via Deserialization in AWS Advanced JDBC Wrapper Exploitation status Not known exploited Fix YesAffected product A AWS Advanced JDBC Wrapper Published 07/01/2026 Severity High CVE-2026-13760OS Command Injection in aws-cdk-lib Docker Bundling Exploitation status Not known exploited Fix YesAffected product A AWS CDK Published 07/01/2026 Severity High CVE-2026-13769Overly permissive File Permissions in AWS CLI Exploitation status Not known exploited Fix YesAffected product A AWS CLI Published 07/01/2026 Severity Medium CVE-2026-13763HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF Exploitation status Not known exploited Fix Not confirmed Affected product A AWS Application Load Balancer Published 06/29/2026 Severity High CVE-2026-13762HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF Exploitation status Public exploit Fix Not confirmed Affected product A Amazon CloudFront Published 06/29/2026 Severity High CVE-2026-12530Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() Exploitation status Not known exploited Fix YesAffected product B bedrock-agentcore Published 06/17/2026 Severity High CVE-2026-11931Insecure Permissions on Authentication Token Cache File in Kiro IDE Exploitation status Not known exploited Fix YesAffected product K Kiro IDE Published 06/15/2026 Severity Medium CVE-2026-12043Heap double-free in AWS Common Runtime aws-c-http Exploitation status Not known exploited Fix YesAffected product A aws-c-http Published 06/12/2026 Severity High CVE-2026-10740Excessive memory allocation in s2n-quic Exploitation status Not known exploited Fix YesAffected product S s2n-quic Published 06/10/2026 Severity Medium CVE-2026-11417OS Command Injection in NodejsFunction Bundling in aws-cdk-lib Exploitation status Not known exploited Fix YesAffected product A AWS Cloud Development Kit library Published 06/10/2026 Severity High CVE-2026-11393Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import Exploitation status Not known exploited Fix YesAffected product A AgentCore CLI Published 06/08/2026 Severity High CVE-2026-11401Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL Exploitation status Not known exploited Fix YesAffected product A AWS Advanced Go Wrapper Published 06/05/2026 Severity High CVE-2026-11400Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL Exploitation status Not known exploited Fix YesAffected product A AWS Advanced JDBC Wrapper Published 06/05/2026 Severity High CVE-2026-10584HTTPS Fallback to HTTP in Graph Explorer Exploitation status Not known exploited Fix YesAffected product G Graph Explorer Published 06/02/2026 Severity High CVE-2026-10591Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths Exploitation status Not known exploited Fix YesAffected product K Kiro IDE Published 06/02/2026 Severity High CVE-2026-9291Insecure Deserialization in Amazon Braket SDK Job Results Processing Exploitation status Not known exploited Fix YesAffected product A Amazon Braket Python SDK Published 05/22/2026 Severity High CVE-2026-9255Tool Execution Without Authorization via Piped Stdin in Kiro CLI Exploitation status Not known exploited Fix YesAffected product K Kiro CLI Published 05/22/2026 Severity High CVE-2026-9133Arbitrary file read in rabbitmq-aws plugin Exploitation status Not known exploited Fix YesAffected product R RabbitMQ AWS Published 05/20/2026 Severity High CVE-2026-8838Remote Code Execution via eval() Injection in amazon-redshift-python-driver Exploitation status Not known exploited Fix YesAffected product A Amazon Redshift connector for Python Published 05/18/2026 Severity Critical CVE-2026-7461OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials Exploitation status Not known exploited Fix YesAffected product A Amazon ECS Agent Published 04/30/2026 Severity High CVE-2026-7426Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCP Exploitation status Not known exploited Fix YesAffected product F FreeRTOS-Plus-TCP Published 04/29/2026 Severity Medium CVE-2026-7425Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP Exploitation status Not known exploited Fix YesAffected product F FreeRTOS-Plus-TCP Published 04/29/2026 Severity Medium CVE-2026-7424Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP Exploitation status Not known exploited Fix YesAffected product F FreeRTOS-Plus-TCP Published 04/29/2026 Severity High CVE-2026-7423Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP Exploitation status Not known exploited Fix YesAffected product F FreeRTOS-Plus-TCP Published 04/29/2026 Severity Medium CVE-2026-7422MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing Exploitation status Not known exploited Fix YesAffected product F FreeRTOS-Plus-TCP Published 04/29/2026 Severity High CVE-2026-7191Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS Exploitation status Not known exploited Fix YesAffected product Q QnABot on AWS Published 04/27/2026 Severity High CVE-2026-6968Multiple Path Traversal Variants in awslabs/tough Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 04/24/2026 Severity High CVE-2026-6967Missing Delegated Metadata Validation in awslabs/tough Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 04/24/2026 Severity High CVE-2026-6966Signature Threshold Bypass in awslabs/tough Delegated Roles Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 04/24/2026 Severity High CVE-2026-6912Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel Exploitation status Not known exploited Fix YesAffected product A AWS Ops Wheel Published 04/24/2026 Severity High CVE-2026-6911Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel Exploitation status Not known exploited Fix YesAffected product A AWS Ops Wheel Published 04/24/2026 Severity Critical CVE-2026-6550Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python Exploitation status Not known exploited Fix YesAffected product A AWS Encryption SDK for Python Published 04/20/2026 Severity Medium CVE-2026-5747Out-of-bounds Write in Firecracker virtio-pci Transport Exploitation status Not known exploited Fix YesAffected product F Firecracker Published 04/07/2026 Severity High CVE-2026-5709AWS Research and Engineering Studio (RES) FileBrowser Command Injection Exploitation status Not known exploited Fix YesAffected product R Research and Engineering Studio (RES) Published 04/06/2026 Severity High CVE-2026-5708Improper Control of User-Modifiable Attributes in RES CreateSession API Exploitation status Not known exploited Fix YesAffected product R Research and Engineering Studio (RES) Published 04/06/2026 Severity High CVE-2026-5707Command Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES) Exploitation status Not known exploited Fix YesAffected product R Research and Engineering Studio (RES) Published 04/06/2026 Severity High CVE-2026-5429Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme Exploitation status Not known exploited Fix YesAffected product K Kiro IDE Published 04/02/2026 Severity High CVE-2026-5190AWS C Event Stream Streaming Decoder Stack Buffer Overflow Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 03/31/2026 Severity High CVE-2026-4428CRL Distribution Point Scope Check Logic Error in AWS-LC Exploitation status Not known exploited Fix YesAffected product A AWS-LC Published 03/19/2026 Severity Critical CVE-2026-4295Arbitrary code execution via crafted project files in Kiro IDE Exploitation status Not known exploited Fix YesAffected product K Kiro IDE Published 03/17/2026 Severity High CVE-2026-4269Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit Exploitation status Not known exploited Fix YesAffected product B Bedrock AgentCore Starter Toolkit Published 03/16/2026 Severity Medium CVE-2026-4270AWS API MCP File Access Restriction Bypass Exploitation status Not known exploited Fix YesAffected product A AWS API MCP Server Published 03/16/2026 Severity Medium CVE-2026-3338PKCS7_verify Signature Validation Bypass in AWS-LC Exploitation status Not known exploited Fix YesAffected product A AWS-LC Published 03/02/2026 Severity High CVE-2026-3337Timing Side-Channel in AES-CCM Tag Verification in AWS-LC Exploitation status Not known exploited Fix YesAffected product A AWS-LC Published 03/02/2026 Severity High CVE-2026-3336PKCS7_verify Certificate Chain Validation Bypass in AWS-LC Exploitation status Not known exploited Fix YesAffected product A AWS-LC Published 03/02/2026 Severity High CVE-2026-1778TLS disabled by default in select aws/sagemaker-python-sdk configurations Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 02/02/2026 Severity High CVE-2026-1777Cleartext transmission of sensitive materials in aws/sagemaker-python-sdk Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 02/02/2026 Severity High CVE-2026-1386Arbitrary Host File Overwrite via Symlink in Firecracker Jailer Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 01/23/2026 Severity Medium