AWS Security Agent: Critical S3 Bucket Verification Flaws Expose Credentials
AWS Security Agent plugin has two nasty vulnerabilities (CVE-2026-87912 and CVE-2026-87913) where missing S3 bucket ownership checks let attackers grab your private source archives—including credentials and infrastructure state. Affected versions: aws-agents-for-devsecops ≤1.0.0 and MCP Server 0.1.0-0.1.5. Update to version 1.1.0+ and 0.2.0+ immediately—this one requires your action.
source: [aws/security-bulletin]