bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

AWS Research and Engineering Studio (RES) Patches Critical Command Injection Flaws

AWS Research and Engineering Studio (RES) has three nasty vulnerabilities (CVE-2026-5707, CVE-2026-5708, CVE-2026-5709) affecting versions up to 2025.12.01. Attackers with valid credentials can execute arbitrary commands as root, escalate privileges to assume host instance profiles, or compromise the cluster-manager EC2 instance. **Action required:** Update to version 2026.03 or later immediately—these are serious remote code execution issues.

source: [aws/security-bulletin]