Critical Command Injection in Amazon ECS Agent for Windows
Amazon ECS Agent versions 1.47.0–1.102.2 have a nasty command injection vulnerability (CVE-2026-7461) when mounting FSx for Windows File Server volumes. An attacker can execute arbitrary code with SYSTEM privileges by crafting malicious credentials in task definitions. If you're running Windows ECS tasks with FSx volumes, you need to update immediately—this one's serious.
source: [aws/security-bulletin]