AWS Advanced JDBC Wrapper: Critical Deserialization Vulnerability in RemoteQueryCachePlugin
AWS Advanced JDBC Wrapper versions 3.3.0 through 4.0.0 have a nasty deserialization flaw (CVE-2026-14265) in RemoteQueryCachePlugin. If you've got this plugin enabled, an attacker with cache write access can inject malicious Java objects that execute arbitrary code on your app server. Update immediately if you're running affected versions—this one requires action.