2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 16:05 UTC
Bulletin ID: 2026-105-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 08:30 AM PDT Description: AWS Security Agent is a managed AWS service that provides AI-powered code security reviews, threat modeling, and penetration testing. We identified CVE-2026-87912, where a missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before version 1.1.0 might allow remote attackers to obtain the private source ar…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-09 21:40 UTC
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-09 16:50 UTC
Bulletin ID: 2026-103-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/09/2026 09:30 AM PDT Description: We identified an issue in awslabs.mysql-mcp-server (an open-source, self-hosted Model Context Protocol server distributed via github.com/awslabs/mcp and PyPI). In affected versions, under certain conditions the read-only enforcement could be circumvented via SQL inline comments, allowing a statement to run that the read-only check was expected to block. The re…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-08 20:10 UTC
Bulletin ID: 2026-102-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/08/2026 12:30 PM PDT Description: A stored cross-site scripting (XSS) issue in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. Affedted products & versions: OpenSearch Dashboards (open-s…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-04 20:15 UTC
Bulletin ID: 2026-101-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 13:00 PM PDT Description: We have identified CVE-2026-85787, an incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. I…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-04 19:55 UTC
Bulletin ID: 2026-097-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:00 AM PDT Description: Amazon awslabs.dynamodb-mcp-server is an open-source Model Context Protocol (MCP) server that enables AI coding assistants to interact with Amazon DynamoDB, including table design, data modeling, and CDK infrastructure generation. We identified CVE-2026-85654, an improper neutralization of special elements used in a template engine in the CDK generator compone…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-04 19:35 UTC
Bulletin ID: 2026-100-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-85786, memory-amplification denial of service via highly compressed data expansion. ion-java 1.12.0 added a GZIP auto-decompression opt-out for CVE-2026-75936, but the implementation of the opt-out in 1.12.0 was insufficient to address the issue. Impacte…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-04 19:15 UTC
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT Description: The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) driver that lets Kubernetes workloads use Amazon EFS file systems. We identified CVE-2026-85781, an issue in the driver's volume-deletion logic. When the controller is configured with the non-default --delete-access-point-root-dir=true option, it did not verify that the EF…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-04 17:40 UTC
Bulletin ID: 2026-098-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:30 AM PDT Description: log4j-cve-2021-44228-hotpatch is a tool which injects a Java agent into a running JVM process. The agent will attempt to patch the lookup() method of all loaded org.apache.logging.log4j.core.lookup.JndiLookup instances to unconditionally return the string "Patched JndiLookup::lookup()". It is designed to address the CVE-2021-44228 remote code execution issue i…
P20
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-03 18:25 UTC
Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software development kit that enables developers to create accelerators for the high-performance accelerator cards on EC2 F2 instances. We identified CVE-2026-85028, where a creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Ki…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-03 17:25 UTC
Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project templates that generate a software project. The @amazon-codecatalyst/blueprints.blueprint npm package is the open source framework that blueprint authors build on, published from github.com/aws/codecatalyst-blueprints. We identified CVE-2026-85012 in the blueprint resynthesis framework. During resynthesis, th…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-02 20:50 UTC
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to cra…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-01 18:40 UTC
Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline component uses an HMAC key to protect the integrity of serialized function payloads stored in S3. We identified an issue where the HMAC secret key is stored in cleartext within pipeline definitions and accessible via the DescribePipeline API. This allows an actor with a role in that account that has p…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-31 18:55 UTC
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We identified CVE-2026-83497 where a remote authenticated user with basic read/search permissions can run arbitrary code on the server by providing a crafted cursor parameter to the plugins/sql endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.8 to…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 18:20 UTC
Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a …
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 17:05 UTC
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the inte…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-25 19:30 UTC
Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the python_repl tool, which executes Python code on the agent's host, and the batch tool, which invokes several other tools in a single call. Before executing code, python_repl prompts the ope…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:20 UTC
Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-77811, a stored cross-site scripting issue in the dashboards-observability plugin in OpenSearch Dashboards. Improper input validation in the integrations static file endpoint allows a remote authenticated actor with write …
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:00 UTC
Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Ath…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 18:10 UTC
Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-20…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-20 22:05 UTC
Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards before 3.8 allows a remote authenticated user with standard data access permissions to execute arbitrary code on the server by sending a crafted JSON payload to the metrics visualization API endpoint. To mitigate this issue, users should upgrade to OpenSearch Das…
P20
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-20 20:25 UTC
Bulletin ID: 2026-084-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Ath…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-18 20:10 UTC
Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most u…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-18 18:30 UTC
Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in the capabilities route handler in OpenSearch Dashboards. The handler does not bound the size of the request payload, which might allow remote attackers to cause a …
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar den…
P5
2026-09-09 18:11 UTC
Security Journalism
The Record · indexed 2026-09-09 18:20 UTC
The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
P0
2026-09-09 16:30 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 16:50 UTC
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
P15
2026-09-09 13:47 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 14:50 UTC
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance […]
P50
2026-09-09 10:49 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 10:50 UTC
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
P10