bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

Firecracker Jailer Symlink Vulnerability Requires Immediate Patching

Firecracker versions 1.13.1 and earlier, plus 1.14.0, have a nasty symlink bug (CVE-2026-1386) that could let attackers overwrite arbitrary host files through the jailer isolation layer. If you're running Firecracker directly, you need to update now—AWS services using Firecracker aren't affected due to their access restrictions, but self-hosted deployments should patch immediately.

source: [aws/security-bulletin]