AWS Security Bulletins
Amazon Web Services publishes security bulletins for issues affecting AWS services, open-source projects it maintains and cross-industry vulnerabilities that touch cloud workloads. For teams running on AWS, a bulletin is the authoritative word on whether the platform is affected and what customers must patch themselves.
CSIRTS.com ingests AWS Security Bulletins every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes security bulletins for AWS services and cloud workloads. Also available via RSS, JSON API and the MCP server.
Latest from AWS Security Bulletins
CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
Browse all 120 advisories from AWS Security Bulletins →
Never miss a AWS Security Bulletins advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.