bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, September 10, 2026

AWS Systems Manager Agent SSRF Vulnerability Requires Immediate Update

AWS Systems Manager Agent versions below 3.3.4851.0 have a server-side request forgery flaw in Session Manager port forwarding. Authenticated users with port-forwarding permissions could bypass security controls to access link-local endpoints and steal temporary IAM credentials. Action required: update SSM Agent immediately on all affected managed nodes to patch this important vulnerability.

source: [aws/security-bulletin]