bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

AWS Ops Wheel v2 Security Flaws Need Your Attention

AWS Ops Wheel v2 (PR-163 and earlier) has two security issues you should know about. CVE-2026-6911 skips JWT token verification in the v2 API, while CVE-2026-6912 leaves Cognito User Pool attributes too open for writing. If you're running this CloudFormation-deployed tool, update immediately—user action is required.

source: [aws/security-bulletin]