bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Tuesday, September 22, 2026

AmazonConnectSalesforceLambda Authorization Bypass – Update Required

AmazonConnectSalesforceLambda versions 5.15–5.24.16 have a critical authorization flaw (CVE-2026-94384) in the sfExecuteAWSService function. An attacker with lambda:InvokeFunction permission can bypass IAM checks and execute privileged AWS operations they shouldn't access. If you're running affected versions, update immediately—this one's a real privilege escalation nightmare.

source: [aws/security-bulletin]