bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Wednesday, September 9, 2026

Critical OS Command Injection in AWS log4j-cve-2021-44228-hotpatch

AWS log4j-cve-2021-44228-hotpatch versions ≤1.3-8.amzn2 have a nasty OS command injection vulnerability (CVE-2026-85656) that lets local users execute arbitrary commands as root. The bug sneaks in when Java process paths contain newline characters. If you're running affected versions on Amazon Linux, update to 1.3-9.amzn2 or later—this one needs your attention.

source: [aws/security-bulletin]