Vendor advisories

AWS Security Bulletins

Browse 111 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked every 15 minutes

111 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
AWS Security BulletinsCVE-2026-81849
Severity not listed

CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devic...

Vendor guidance

Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources.

AWS Security BulletinsCVE-2026-77811
Severity not listed

CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-...

Vendor guidance

Affected products & versions: OpenSearch Dashboards dashboards-observability plugin (open-source, self-managed): - Affected: versions before 3.4 and versions before 2.19.6 - Fixed: versions 3.4 and 2.19.6 Amazon OpenS...

AWS Security BulletinsCVE-2026-18420
Severity not listed

CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin

Bulletin ID: 2026-085-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:30 PM PDT Description: Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards before 3.8 allows a remote authenticated ...

Vendor guidance

To mitigate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

AWS Security BulletinsCVE-2026-18952
Severity not listed

CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-18952, a missing input validation issue in ...

Vendor guidance

Impacted Versions: OpenSearch Security Analytics Plugin (open-source, self-managed): - Affected: >= 2.15.0 - Fixed: >= 3.5.0 Amazon OpenSearch Service (AWS Managed): - Affected: Domains running engine versions >= 2.15...

AWS Security BulletinsCVE-2026-18428
Severity not listed

CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration wit...

Vendor guidance

Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.13 to v3.6 - Fixed: versions 3.7 and 2.19.6 Amazon OpenSearch Service (AWS Managed): - Affected: v2.13 to v3.5 - Fixed: v...

AWS Security BulletinsCVE-2026-19311
Severity not listed

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-19311, a missing authorization issue in the...

Vendor guidance

Impacted versions: OpenSearch Alerting Plugin (open-source, self-managed): - Affected: 2.4.0 through 2.19.5, 3.0.0 through 3.7.0 - Fixed: 2.19.6, 3.8.0 Amazon OpenSearch Service (AWS Managed): - Affected: All domains ...

AWS Security BulletinsCVE-2026-18954
Severity not listed

CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server

Bulletin ID: 2026-076-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 13:00 PM PDT Description: Amazon DocumentDB MCP Server is an open-source Model Context Protocol (MCP) server that enables AI assistants to interact with Amazon Docume...

AWS Security BulletinsCVE-2026-75897
Severity not listed

CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We ...

Vendor guidance

- Fixed: 3.8.0 Amazon OpenSearch Service (AWS Managed): - Affected: Engine versions OpenSearch 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, and 3.5, and Elasticsearch-compatibility versions using Kibana 7.9 and 7.10.

AWS Security BulletinsCVE-2026-7791
Severity not listed

CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent

Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/04 15:30 PM PDT Description: Amazon Skylight Workspace Config Service ( slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system ...

AWS Security BulletinsCVE-2026-12530
Severity not listed

CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

Bulletin ID: 2026-044-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/17/2026 14:15 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents o...

AWS Security Bulletins
Severity not listed

Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel

Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:45 PM PDT This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching inform...

Vendor guidance

Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information.

AWS Security Bulletins
Severity not listed

Issues with Amazon Athena ODBC Driver

Bulletin ID: 2026-013-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/03 13:00 PM PDT Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athe...

Vendor guidance

We identified the following: - CVE-2026-5485: OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) - CVE-2026-35558: Improper neutralization of special elements in authenticati...

AWS Security BulletinsCVE-2026-50195
Severity not listed

Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262

Bulletin ID: 2026-046-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/18/2026 17:30 PM PDT Description: containerd is an open-source container runtime used by Kubernetes via the Container Runtime Interface (CRI) plugin. It underpins AWS managed...

AWS Security BulletinsCVE-2026-6550
Severity not listed

CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python

Bulletin ID: 2026-017-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/20 12:45 PM PDT Description: AWS Encryption SDK (ESDK) for Python is a client-side encryption library. We identified CVE-2026-6550, which describes an issue with a key c...

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.