IntelFreed A CYBERSECURITY INTELLIGENCE FEED

NEWS

Cybersecurity reportings, advisories, and research. 187 matching records.
Last update // 2026-08-22 03:55 UTC
CYBER INTEL TEMPERATURE
For today's cybersecurity intelligence
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
RESET
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-015-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/07 15:30 PM PDT Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747, an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with r…

Cloud SecurityLinuxVulnerabilitiesCVE-2026-5747
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-076-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 13:00 PM PDT Description: Amazon DocumentDB MCP Server is an open-source Model Context Protocol (MCP) server that enables AI assistants to interact with Amazon DocumentDB databases. We identified CVE-2026-18954, an incorrect authorization issue where write-capable aggregation pipeline stages ($out, $merge) bypass the read-only mode enforcement logic, potentially allowing an authenticat…

Cloud SecurityVulnerabilitiesCVE-2026-18954
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE-2026-19311, a missing authorization issue in the Execute Monitor API of the OpenSearch Alerting plugin. This issue may allow an authenticated user with the alerting_full_access role to read, modify, or delete arbitrary index data via a crafted inline monitor request wit…

Cloud SecurityVulnerabilitiesCVE-2026-19311
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-035-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/22/2026 09:45 AM PDT Description: Kiro CLI is a command-line AI coding assistant that enables developers to interact with AI models to execute code, manage files, and run shell commands. We identified CVE-2026-9255, an issue where missing input source validation in the tool authorization prompt could allow a local actor to execute arbitrary tools, including shell commands, without user approva…

Cloud SecurityVulnerabilitiesCVE-2026-9255
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-15415 - Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-060-AWS Scope: AWS Content Type: Important (requires attention) / Informational Publication Date: 07/17/2026 12:45 PM PDT Description: AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. We identified CVE-2026-15415, where improper limitation of a pathname to a restricted directory in the linti…

Cloud SecurityVulnerabilitiesCVE-2026-15415
P5
2026-08-20 21:35 UTC
Vendor Research

Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-018-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 09:15 AM PDT Description: AWS Ops Wheel is an open-source tool that helps teams make random selections using a virtual spinning wheel, deployed into customer AWS accounts via CloudFormation. CVE-2026-6911 relates to an issue where JWT token signature verification was not enforced in the v2 API. CVE-2026-6912 relates to an issue in the v2 Cognito User Pool configuration where attribute …

Cloud SecurityVulnerabilitiesCVE-2026-6911CVE-2026-6912
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-043-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/12/2026 11:45 AM PDT Description: AWS Common Runtime aws-c-http is a HTTP client library used by AWS SDKs for handling http requests to AWS services. We identified CVE-2026-12043, an issue where improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote actor operating a server to cause memory corruption on a connecting client applic…

Cloud SecurityVulnerabilitiesCVE-2026-12043
P5
2026-08-20 21:35 UTC
Vendor Research

Arbitrary code execution via crafted project files in Kiro IDE

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-009-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/17 12:15 PM PDT Description: Kiro is an AI-powered IDE for agentic software development. We identified CVE-2026-4295, where improper trust boundary enforcement allowed arbitrary code execution when a user opened a maliciously crafted project directory. Impacted versions: < 0.8.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security…

Cloud SecurityVulnerabilitiesCVE-2026-4295
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-31431

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-026-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/06 17:30 PM PDT Description: Amazon is aware of an issue in the Linux kernel (CVE-2026-31431) that could potentially allow an authenticated local user to escalate privileges. With the exception of the services listed below, AWS customers are not affected. See below for specific guidance on affected services. As a best practice, AWS recommends that you apply all security patches and softwa…

Cloud SecurityLinuxVulnerabilitiesCVE-2026-31431
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-069-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 12:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the http_request tool for making HTTP API requests. We identified CVE-2026-18394, an incorrect authorization issue in the http_request tool. Operators can use the HTTP_REQUEST_TOKEN_CONFIG allowlist to bind a cr…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-18394
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-052-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/06/2026 13:45 PM PDT Description: Amazon mcp-gateway-registry is an open-source gateway and registry for Model Context Protocol (MCP) servers, providing centralized discovery, authentication/authorization, and proxying of MCP tools for AI agents. We identified CVE-2026-14471, an issue in the metrics-service retention policy management component where a caller-supplied table_name value is inter…

AI SecurityCloud SecurityLaw EnforcementMicrosoftVulnerabilitiesCVE-2026-14471
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643, a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authent…

Cloud SecurityVulnerabilitiesCVE-2026-15643
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-10740 - Excessive memory allocation in s2n-quic

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-041-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 10:45 AM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified CVE-2026-11417, an OS command injection issue in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) that may allow an actor who controls the value of one or more bun…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-10740CVE-2026-11417
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via netwo…

Cloud SecurityVulnerabilitiesCVE-2026-18654
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-4270 - AWS API MCP File Access Restriction Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-007-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 09:15 AM PDT Description: The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. This server acts as a bridge between AI assistants and AWS services, allowing …

Cloud SecurityVulnerabilitiesCVE-2026-4270
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-037-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 08:45 AM PDT Description: Kiro is an agentic IDE users install on their desktop. We identified CVE-2026-10591. Insufficient access control restrictions in the file write tool in Kiro IDE prior to version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabl…

Cloud SecurityVulnerabilitiesCVE-2026-10591
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-7461 - OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-024-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/30 13:30 PM PDT Description: Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. The Amazon ECS agent supports mounting FSx for Windows File Server volumes in task definitions on Windows EC2 instances. We identified CVE-2026-7461, a command injection issue in FSx vo…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-7461
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-5190 - AWS C Event Stream Streaming Decoder Stack Buffer Overflow

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/31 10:15 AM PDT Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190. AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes…

Cloud SecurityVulnerabilitiesCVE-2026-5190
P5
2026-08-20 21:35 UTC
Vendor Research

Ongoing updates on Copy.fail and variants

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available. Please see below for current patching timelines for affected services rel…

Cloud SecurityLinuxVulnerabilities
P10
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch …

Cloud SecurityVulnerabilitiesCVE-2026-18830
P5
2026-08-20 21:35 UTC
Vendor Research

Issues with AWS Research and Engineering Studio (RES)

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-014-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/06 14:00 PM PDT Description: Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES). CVE-2026-5707: Unsanitized input in an OS Command in the virtual desktop session name hand…

Cloud SecurityVulnerabilitiesCVE-2026-5707CVE-2026-5708CVE-2026-5709
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-15895: OS command injection in jsii-diff in AWS jsii

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT Description: jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool. Impacted versions: < 1.131.0 Please refer to the artic…

Cloud SecurityVulnerabilitiesCVE-2026-15895
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar den…

Cloud SecurityVulnerabilitiesCVE-2026-18428
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-13769 – Insecure file permissions in AWS CLI

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-049-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other l…

Cloud SecurityVulnerabilitiesCVE-2026-13769
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT Description: Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio). We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a ma…

Cloud SecurityVulnerabilitiesCVE-2026-12957CVE-2026-12958
P5
2026-08-20 21:35 UTC
Vendor Research

Security Findings in SageMaker Python SDK

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-004-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/02/02 14:30 PM PST Description: CVE-2026-1777 - Exposed HMAC in SageMaker Python SDK SageMaker Python SDK’s remote functions feature uses a per‑job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3. We identified an issue where the HMAC secret key is stored in environment variables and disclosed via the DescribeTrainingJob API. This allows third p…

Cloud SecurityVulnerabilitiesCVE-2026-1777CVE-2026-1778
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:20 PM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset…

Cloud SecurityVulnerabilitiesCVE-2026-7424
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-11400 and CVE-2026-11401

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-039-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/025/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400(JDBC) and CVE-2026-11401(Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be execute…

Cloud SecurityVulnerabilitiesCVE-2026-11400CVE-2026-11401
P15
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796, an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitra…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-16796
P5
2026-08-20 21:35 UTC
Vendor Research

Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-029-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 18:45 PM PDT This is an ongoing issue. Information is subject to change. Please refer to our Security Bulletin (ID: 2026-030-AWS) for the most updated patching information. Description: Amazon is aware of CVE-2026-46300, a report of an additional privilege escalation issue in the Linux kernel related to the DirtyFrag, copy.fail class of issues (CVE-2026-43284). The proof of concept use…

Cloud SecurityLinuxSecurity ResearchVulnerabilitiesCVE-2026-43284CVE-2026-46300
P15
1 2 3 4