AWS Security Bulletins
Amazon Web Services publishes security bulletins for issues affecting AWS services, open-source projects it maintains and cross-industry vulnerabilities that touch cloud workloads. For teams running on AWS, a bulletin is the authoritative word on whether the platform is affected and what customers must patch themselves.
CSIRTS.com ingests AWS Security Bulletins every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes security bulletins for AWS services and cloud workloads. Also available via RSS, JSON API and the MCP server.
Latest from AWS Security Bulletins
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Browse all 108 advisories from AWS Security Bulletins →
Never miss a AWS Security Bulletins advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.