bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Wednesday, August 12, 2026

AWS SDK for C++ Base64 Decoder Vulnerabilities Require Immediate Update

AWS SDK for C++ versions up to 1.11.861 contain two memory-safety bugs (CVE-2026-19642 and CVE-2026-19643) in the Base64 decoder that could crash your app or corrupt memory. CVE-2026-19642 causes out-of-bounds writes, while CVE-2026-19643 triggers out-of-bounds reads on certain platforms. Yes, you need to act—update your SDK immediately if you're using an affected version. Remote code execution hasn't been demonstrated, but the impact is real for any process decoding untrusted Base64 data.

source: [aws/security-bulletin]

OpenSearch Alerting Plugin: Authorization Bypass Requires Immediate Patching

OpenSearch Alerting Plugin has a nasty authorization flaw (CVE-2026-19311) that lets authenticated users with alerting_full_access role read, modify, or delete arbitrary index data through crafted monitor requests. Affected versions: 2.4.0–2.19.5 and 3.0.0–3.7.0 (self-managed), plus AWS OpenSearch Service domains on engines 2.4–3.5. Action required: upgrade to 2.19.6, 3.8.0, or service software R20260428-P3 immediately.

source: [aws/security-bulletin]

also that day:

Tuesday, August 11, 2026

AWS Landing Zone Accelerator Gets C5:2020 Compliance Stamp

AWS just dropped an independent assessment report for Landing Zone Accelerator on AWS Artifact, proving it meets Germany's strict C5:2020 cloud security standards. If you're deploying infrastructure in Europe and need to tick compliance boxes without reinventing the wheel, this assessment gives you a solid foundation to build on.

source: [aws/security-blog]

also that day:

Monday, August 10, 2026

AWS IAM Account Access Manager: Flexible Role Assignment Just Got Easier

AWS Identity and Access Management rolled out account access manager, letting admins assign IAM roles directly to workforce users through IAM Identity Center—no extra cost, available across all AWS Commercial Regions. This bridges the gap between centralized federation and granular IAM role flexibility, giving you the best of both worlds without the usual trade-offs.

source: [aws/whats-new]

Amazon OpenSearch Serverless Scales to 10,000 Collections Per Group

Amazon OpenSearch Serverless just bumped its collection limit from 1,500 to 10,000 per collection group, letting you pack way more multi-tenant workloads into a single shared compute pool. This means better cost efficiency and resource utilization across all AWS Regions where nextgen OpenSearch Serverless is available—perfect for scaling those tenant-per-collection architectures without spinning up extra infrastructure.

source: [aws/whats-new]

also that day: