Vendor
Amazon Web Services vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 47 vulnerabilities in Amazon Web Services: 0 in the last 7 days and 14 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-87913, was published on 10 September 2026. 7 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 2
- Exploited in the wild
- 0
About Amazon Web Services
Amazon Web Services (AWS) is a cloud computing platform providing infrastructure, platform, and software-as-a-service offerings.
Amazon Web Services technologies
- Amazon Web Services FreeRTOS-Plus-TCP4
- Amazon Web Services Aws-C-Io3
- Amazon Web Services AWS IoT Device SDK v2 for C++3
- Amazon Web Services AWS IoT Device SDK v2 for Java3
- Amazon Web Services AWS IoT Device SDK v2 for Node.js3
- Amazon Web Services AWS IoT Device SDK v2 for Python3
- Amazon Web Services Research and Engineering Studio3
Latest Amazon Web Services vulnerabilities
- CVE-2026-87913: AWS Security Agent MCP server missing S3 bucket ownership verificationmediumCVSS 5.9EPSS 0.4%
- CVE-2026-18952: OpenSearch Security Analytics Plugin missing input validationhigh
- CVE-2026-18953: AWS Transform MCP Server improper pathname validationhigh
- CVE-2026-75897: OpenSearch Dashboards uncontrolled resource consumption in capabilities routehighCVSS 7.5
- CVE-2026-18481: AWS Ops Wheel stored XSS in participant URL handlinghighCVSS 7.3
- CVE-2026-15737: AWS Bedrock AgentCore Python SDK sensitive information disclosure in OpenTelemetry spanshighCVSS 5.7
- AWS jsii-diff command injection in npm package loadinghighCVSS 7.8
- CVE-2026-15895: AWS jsii-diff OS command injection in npm package loadinghighCVSS 7.8EPSS 1.1%
- CVE-2026-15746: Amazon Strands Agents Tools SSRF in elasticsearch_memory toolhighCVSS 6.5
- CVE-2026-14904: AWS Research and Engineering Studio Arbitrary File Read in Auth.GetUserPrivateKeyhighCVSS 6.5
- CVE-2026-89090: GO-2026-5764 - DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in…highCVSS 3.1EPSS 0.3%
- CVE-2026-14265: AWS Advanced JDBC Wrapper RCE in RemoteQueryCachePluginhighCVSS 7.5
- CVE-2026-13769: AWS AWS CLI insecure file permissions in credential subcommandshighCVSS 5.5EPSS 0.2%
- CVE-2026-13762: AWS CloudFront WAF bypass via HTTP/2 request body fragmentationcriticalCVSS 9.8
- CVE-2026-7461: GO-2026-5353 - Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure in…highCVSS 3.1EPSS 0.8%
- CVE-2026-12958: AWS Language Servers arbitrary file write via symlink validation bypasshighCVSS 7.8EPSS 0.2%
- CVE-2026-12957: AWS Language Servers arbitrary code execution in trusted workspaceshighCVSS 7.8EPSS 0.2%
- CVE-2026-12043: AWS aws-c-http memory corruption in HPACK resizinghighCVSS 8.8
- CVE-2026-11400: AWS Advanced JDBC Wrapper privilege escalation in GlobalDatabasePluginhighCVSS 8EPSS 0.3%
- CVE-2026-10584: AWS Graph Explorer cleartext transmission via HTTPS fallbackhighCVSS 5.9
- CVE-2026-9291: AWS Amazon Braket Python SDK insecure deserialization in job results processinghighCVSS 7.1EPSS 0.7%
- CVE-2026-9255: Amazon Kiro CLI unauthorized command execution via piped stdinhighCVSS 7.8EPSS 0.0%
- CVE-2026-8838: AWS amazon-redshift-python-driver code injection in vector_incriticalCVSS 9.8EPSS 0.8%
- CVE-2026-8686: FreeRTOS coreMQTT denial of service in MQTT v5.0 property parserhighCVSS 7.5
- CVE-2026-7425: Amazon FreeRTOS-Plus-TCP memory safety issues in IPv6 Router Advertisementhigh
Most severe Amazon Web Services vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-8838: AWS amazon-redshift-python-driver code injection in vector_incriticalCVSS 9.8EPSS 0.8%
- CVE-2026-13762: AWS CloudFront WAF bypass via HTTP/2 request body fragmentationcriticalCVSS 9.8
- CVE-2026-5708: AWS Research and Engineering Studio privilege escalation in session creationhighCVSS 8.8EPSS 0.8%
- CVE-2026-12043: AWS aws-c-http memory corruption in HPACK resizinghighCVSS 8.8
- CVE-2026-11400: AWS Advanced JDBC Wrapper privilege escalation in GlobalDatabasePluginhighCVSS 8EPSS 0.3%
- CVE-2026-15895: AWS jsii-diff OS command injection in npm package loadinghighCVSS 7.8EPSS 1.1%
- CVE-2026-5485: Amazon Athena ODBC driver OS command injection in Linux authentication componenthighCVSS 7.8EPSS 0.7%
- CVE-2026-12958: AWS Language Servers arbitrary file write via symlink validation bypasshighCVSS 7.8EPSS 0.2%
- CVE-2026-12957: AWS Language Servers arbitrary code execution in trusted workspaceshighCVSS 7.8EPSS 0.2%
- CVE-2026-9255: Amazon Kiro CLI unauthorized command execution via piped stdinhighCVSS 7.8EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 3 | 1 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 4 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 4 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/amazon-web-services.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Amazon Web Services vulnerabilities", https://junglewise.ai/threats/vendors/amazon-web-services, 26 September 2026.