{"schema_version":1,"title":"Amazon AWS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 128 vulnerabilities in Amazon AWS: 2 in the last 7 days and 67 in the last 90 days, 8 of them critical and 1 exploited in the wild. The most recent, CVE-2026-96883, was published on 24 September 2026.","url":"https://junglewise.ai/threats/technologies/aws","json_url":"https://junglewise.ai/threats/technologies/aws.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/aws","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":116,"all_time":128,"critical":8,"exploited":1,"last_7_days":2,"last_30_days":33,"last_90_days":67,"last_365_days":123},"latest":[{"cve":"CVE-2026-96883","cvss":8.8,"epss":0.0065,"slug":"cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution","title":"pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authen","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:35.24+00:00","url":"https://junglewise.ai/threats/cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution"},{"cve":"CVE-2026-94384","cvss":8.1,"epss":0.0025,"slug":"cve-2026-94384-amazon-connect-salesforce-lambda-authorization-bypass-in","title":"Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission","severity":"high","exploited":false,"published_at":"2026-09-22T18:17:32.21+00:00","url":"https://junglewise.ai/threats/cve-2026-94384-amazon-connect-salesforce-lambda-authorization-bypass-in"},{"cve":"CVE-2026-92943","cvss":8.1,"epss":0.0038,"slug":"cve-2026-92943-aws-iot-device-sdk-for-python-certificate-host-mismatch","title":"Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through","severity":"high","exploited":false,"published_at":"2026-09-17T20:18:59.333+00:00","url":"https://junglewise.ai/threats/cve-2026-92943-aws-iot-device-sdk-for-python-certificate-host-mismatch"},{"cve":"CVE-2026-86831","cvss":8.7,"epss":0.0064,"slug":"cve-2026-86831-amazon-eks-aws-network-policy-agent-cross-namespace-networkpolicy","title":"Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an","severity":"high","exploited":false,"published_at":"2026-09-16T20:17:36.98+00:00","url":"https://junglewise.ai/threats/cve-2026-86831-amazon-eks-aws-network-policy-agent-cross-namespace-networkpolicy"},{"cve":"CVE-2026-86830","cvss":7.2,"epss":0.0069,"slug":"cve-2026-86830-aws-team-privilege-escalation-in-iam-identity-center","title":"Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 migh","severity":"high","exploited":false,"published_at":"2026-09-14T19:17:52.523+00:00","url":"https://junglewise.ai/threats/cve-2026-86830-aws-team-privilege-escalation-in-iam-identity-center"},{"cve":"CVE-2026-89332","cvss":5.5,"epss":0.0018,"slug":"cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written","title":"Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow","severity":"high","exploited":false,"published_at":"2026-09-11T20:19:23.67+00:00","url":"https://junglewise.ai/threats/cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written"},{"cve":"CVE-2026-18061","cvss":5.9,"epss":0.0027,"slug":"cve-2026-18061-aws-advanced-jdbc-wrapper-xxe-in-remotequerycacheplugin","title":"Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might","severity":"high","exploited":false,"published_at":"2026-09-11T17:17:08.927+00:00","url":"https://junglewise.ai/threats/cve-2026-18061-aws-advanced-jdbc-wrapper-xxe-in-remotequerycacheplugin"},{"cve":"CVE-2026-89065","cvss":7.1,"epss":0.0019,"slug":"cve-2026-89065-projen-path-traversal-in-file-manifest-cleanup","title":"Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers t","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:49.253+00:00","url":"https://junglewise.ai/threats/cve-2026-89065-projen-path-traversal-in-file-manifest-cleanup"},{"cve":"CVE-2026-89049","cvss":9.9,"epss":0.0066,"slug":"cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding","title":"A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts","severity":"critical","exploited":false,"published_at":"2026-09-10T19:17:42.373+00:00","url":"https://junglewise.ai/threats/cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding"},{"cve":"CVE-2026-85228","cvss":9.1,"epss":0.0054,"slug":"cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer","title":"An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms","severity":"critical","exploited":false,"published_at":"2026-09-10T17:17:06.437+00:00","url":"https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer"},{"cve":"CVE-2026-87912","cvss":5.9,"epss":0.0044,"slug":"cve-2026-87912-aws-security-agent-missing-s3-bucket-ownership-verification","title":"A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remo","severity":"high","exploited":false,"published_at":"2026-09-10T16:18:07.037+00:00","url":"https://junglewise.ai/threats/cve-2026-87912-aws-security-agent-missing-s3-bucket-ownership-verification"},{"cve":"CVE-2026-18952","slug":"cve-2026-18952-opensearch-security-analytics-plugin-missing-input-validation","title":"OpenSearch Security Analytics Plugin missing input validation","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:25+00:00","url":"https://junglewise.ai/threats/cve-2026-18952-opensearch-security-analytics-plugin-missing-input-validation"},{"cve":"CVE-2026-19111","slug":"cve-2026-19111-aws-strands-agents-tools-insecure-direct-object-reference-in","title":"AWS Strands Agents Tools insecure direct object reference in memory tools","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:25+00:00","url":"https://junglewise.ai/threats/cve-2026-19111-aws-strands-agents-tools-insecure-direct-object-reference-in"},{"cve":"CVE-2026-18954","slug":"cve-2026-18954-amazon-aws-labs-documentdb-mcp-server-authorization-bypass-in","title":"Amazon AWS Labs DocumentDB MCP Server authorization bypass in aggregation pipeline","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:25+00:00","url":"https://junglewise.ai/threats/cve-2026-18954-amazon-aws-labs-documentdb-mcp-server-authorization-bypass-in"},{"cve":"CVE-2026-19642","slug":"cve-2026-19642-aws-sdk-for-c-memory-safety-issues-in-base64-decoder","title":"AWS SDK for C++ memory safety issues in Base64 decoder","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:25+00:00","url":"https://junglewise.ai/threats/cve-2026-19642-aws-sdk-for-c-memory-safety-issues-in-base64-decoder"},{"cve":"CVE-2026-18953","slug":"cve-2026-18953-aws-transform-mcp-server-improper-pathname-validation","title":"AWS Transform MCP Server improper pathname validation","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:24+00:00","url":"https://junglewise.ai/threats/cve-2026-18953-aws-transform-mcp-server-improper-pathname-validation"},{"cve":"CVE-2026-19311","cvss":0,"slug":"cve-2026-19311-opensearch-alerting-plugin-missing-authorization","title":"OpenSearch Alerting Plugin missing authorization","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:24+00:00","url":"https://junglewise.ai/threats/cve-2026-19311-opensearch-alerting-plugin-missing-authorization"},{"cve":"CVE-2026-18428","slug":"cve-2026-18428-opensearch-sql-plugin-async-query-validation-bypass","title":"OpenSearch SQL Plugin async query validation bypass","severity":"high","exploited":false,"published_at":"2026-09-09T21:30:11+00:00","url":"https://junglewise.ai/threats/cve-2026-18428-opensearch-sql-plugin-async-query-validation-bypass"},{"cve":"CVE-2026-75897","cvss":7.5,"slug":"cve-2026-75897-opensearch-dashboards-uncontrolled-resource-consumption-in","title":"OpenSearch Dashboards uncontrolled resource consumption in capabilities route","severity":"high","exploited":false,"published_at":"2026-09-09T21:30:11+00:00","url":"https://junglewise.ai/threats/cve-2026-75897-opensearch-dashboards-uncontrolled-resource-consumption-in"},{"cve":"CVE-2026-75935","slug":"cve-2026-75935-amazon-ion-java-memory-amplification-denial-of-service","title":"Amazon ion-java memory amplification denial of service","severity":"high","exploited":false,"published_at":"2026-09-09T21:30:11+00:00","url":"https://junglewise.ai/threats/cve-2026-75935-amazon-ion-java-memory-amplification-denial-of-service"},{"cve":"CVE-2026-85788","cvss":5.5,"epss":0.0018,"slug":"cve-2026-85788-aws-labs-mysql-mcp-server-read-only-enforcement-bypass-via-sql","title":"Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent","severity":"high","exploited":false,"published_at":"2026-09-09T17:17:49.937+00:00","url":"https://junglewise.ai/threats/cve-2026-85788-aws-labs-mysql-mcp-server-read-only-enforcement-bypass-via-sql"},{"cve":"CVE-2026-84942","cvss":8.7,"epss":0.0054,"slug":"cve-2026-84942-opensearch-dashboards-stored-xss-via-vega-expression-function","title":"Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with d","severity":"high","exploited":false,"published_at":"2026-09-08T20:18:51.307+00:00","url":"https://junglewise.ai/threats/cve-2026-84942-opensearch-dashboards-stored-xss-via-vega-expression-function"},{"cve":"CVE-2026-85787","cvss":6.5,"epss":0.0034,"slug":"cve-2026-85787-amazon-postgres-mcp-server-sql-validation-bypass","title":"An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might al","severity":"high","exploited":false,"published_at":"2026-09-04T21:17:27.057+00:00","url":"https://junglewise.ai/threats/cve-2026-85787-amazon-postgres-mcp-server-sql-validation-bypass"},{"cve":"CVE-2026-85786","cvss":7.5,"epss":0.0058,"slug":"cve-2026-85786-amazon-ion-java-memory-amplification-denial-of-service","title":"Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a","severity":"high","exploited":false,"published_at":"2026-09-04T20:17:33.153+00:00","url":"https://junglewise.ai/threats/cve-2026-85786-amazon-ion-java-memory-amplification-denial-of-service"},{"cve":"CVE-2026-85781","cvss":8.7,"epss":0.0044,"slug":"cve-2026-85781-amazon-efs-csi-driver-insufficient-access-point-ownership","title":"Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an au","severity":"high","exploited":false,"published_at":"2026-09-04T19:17:34.157+00:00","url":"https://junglewise.ai/threats/cve-2026-85781-amazon-efs-csi-driver-insufficient-access-point-ownership"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":5},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-09-07","critical":2,"exploited":0,"vulnerabilities":17},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"related":[{"name":"Amazon Athena Odbc","slug":"athena-odbc","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/athena-odbc"},{"name":"Amazon Freertos","slug":"freertos","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/freertos"},{"name":"Amazon FreeRTOS Kernel","slug":"freertos-kernel","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/freertos-kernel"},{"name":"Amazon Strands-Agents-Tools","slug":"strands-agents-tools","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/strands-agents-tools"},{"name":"Amazon Engineering Studio","slug":"engineering-studio","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/engineering-studio"},{"name":"Amazon Research","slug":"research","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/research"},{"name":"Amazon SageMaker Python SDK","slug":"sagemaker-python-sdk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/sagemaker-python-sdk"}],"technology":{"hub":true,"name":"Amazon AWS","slug":"aws","vendor":{"name":"Amazon","slug":"amazon","url":"https://junglewise.ai/threats/vendors/amazon"},"aliases":[],"homepage":"https://aws.amazon.com/","description":"A comprehensive cloud computing platform providing a variety of infrastructure and software services.","url":"https://junglewise.ai/threats/technologies/aws"},"most_severe":[{"cve":"CVE-2026-31431","cvss":7.8,"epss":0.0257,"slug":"cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling","title":"Linux Kernel crypto algif_aead improper memory handling","severity":"critical","exploited":true,"published_at":"2026-04-22T09:16:21.27+00:00","url":"https://junglewise.ai/threats/cve-2026-31431-linux-kernel-crypto-algif-aead-improper-memory-handling"},{"cve":"CVE-2026-89049","cvss":9.9,"epss":0.0066,"slug":"cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding","title":"A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts","severity":"critical","exploited":false,"published_at":"2026-09-10T19:17:42.373+00:00","url":"https://junglewise.ai/threats/cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding"},{"cve":"CVE-2026-77810","cvss":9.9,"epss":0.0063,"slug":"cve-2026-77810-aws-athena-federated-query-neptune-connector-credential-exposure","title":"In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplyi","severity":"critical","exploited":false,"published_at":"2026-08-21T20:16:45.53+00:00","url":"https://junglewise.ai/threats/cve-2026-77810-aws-athena-federated-query-neptune-connector-credential-exposure"},{"cve":"CVE-2026-8838","cvss":9.8,"epss":0.008,"slug":"cve-2026-8838-aws-amazon-redshift-python-driver-code-injection-in-vector-in","title":"AWS amazon-redshift-python-driver code injection in vector_in","severity":"critical","exploited":false,"published_at":"2026-05-18T21:16:41.623+00:00","url":"https://junglewise.ai/threats/cve-2026-8838-aws-amazon-redshift-python-driver-code-injection-in-vector-in"},{"cve":"CVE-2026-13762","cvss":9.8,"slug":"cve-2026-13762-aws-cloudfront-waf-bypass-via-http-2-request-body-fragmentation","title":"AWS CloudFront WAF bypass via HTTP/2 request body fragmentation","severity":"critical","exploited":false,"published_at":"2026-06-29T20:17:33.123+00:00","url":"https://junglewise.ai/threats/cve-2026-13762-aws-cloudfront-waf-bypass-via-http-2-request-body-fragmentation"},{"cve":"CVE-2026-85228","cvss":9.1,"epss":0.0054,"slug":"cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer","title":"An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms","severity":"critical","exploited":false,"published_at":"2026-09-10T17:17:06.437+00:00","url":"https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer"},{"cve":"CVE-2026-11393","cvss":9,"epss":0.0034,"slug":"cve-2026-11393-aws-agentcore-cli-code-injection-in-bedrock-agent-import","title":"AWS AgentCore CLI code injection in Bedrock Agent import","severity":"critical","exploited":false,"published_at":"2026-06-08T19:16:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-11393-aws-agentcore-cli-code-injection-in-bedrock-agent-import"},{"cve":"CVE-2025-4318","cvss":4,"epss":0.0094,"slug":"cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui","title":"AWS Amplify Studio eval injection in amplify-codegen-ui","severity":"critical","exploited":false,"published_at":"2026-07-30T20:57:24+00:00","url":"https://junglewise.ai/threats/cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui"},{"cve":"CVE-2026-5707","cvss":8.8,"epss":0.0099,"slug":"cve-2026-5707-aws-research-and-engineering-studio-os-command-injection-in","title":"AWS Research and Engineering Studio OS command injection in session name handling","severity":"high","exploited":false,"published_at":"2026-04-06T22:16:25.263+00:00","url":"https://junglewise.ai/threats/cve-2026-5707-aws-research-and-engineering-studio-os-command-injection-in"},{"cve":"CVE-2026-83497","cvss":8.8,"epss":0.0096,"slug":"cve-2026-83497-opensearch-sql-plugin-unrestricted-java-deserialization-in-cursor","title":"Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated","severity":"high","exploited":false,"published_at":"2026-08-31T19:17:24.327+00:00","url":"https://junglewise.ai/threats/cve-2026-83497-opensearch-sql-plugin-unrestricted-java-deserialization-in-cursor"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}