bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Thursday, September 10, 2026

AWS Systems Manager Agent SSRF Vulnerability Requires Immediate Update

AWS Systems Manager Agent versions below 3.3.4851.0 have a server-side request forgery flaw in Session Manager port forwarding. Authenticated users with port-forwarding permissions could bypass security controls to access link-local endpoints and steal temporary IAM credentials. Action required: update SSM Agent immediately on all affected managed nodes to patch this important vulnerability.

source: [aws/security-bulletin]

Deep Java Library Integer Overflow Vulnerability Requires Immediate Action

Deep Java Library (DJL) versions 0.13.0 through 0.36.0 have a critical integer overflow bug (CVE-2026-85228) in tensor buffer validation that could let remote attackers leak memory or crash your app. The vulnerability affects all platforms and requires user action—upgrade to DJL 0.37.0 or later ASAP. Amazon's already patched it, so no excuses for staying vulnerable here.

source: [aws/security-bulletin]

also that day:

Wednesday, September 9, 2026

AWS Security Agent: Critical S3 Bucket Verification Flaws Expose Credentials

AWS Security Agent plugin has two nasty vulnerabilities (CVE-2026-87912 and CVE-2026-87913) where missing S3 bucket ownership checks let attackers grab your private source archives—including credentials and infrastructure state. Affected versions: aws-agents-for-devsecops ≤1.0.0 and MCP Server 0.1.0-0.1.5. Update to version 1.1.0+ and 0.2.0+ immediately—this one requires your action.

source: [aws/security-bulletin]

Critical OS Command Injection in AWS log4j-cve-2021-44228-hotpatch

AWS log4j-cve-2021-44228-hotpatch versions ≤1.3-8.amzn2 have a nasty OS command injection vulnerability (CVE-2026-85656) that lets local users execute arbitrary commands as root. The bug sneaks in when Java process paths contain newline characters. If you're running affected versions on Amazon Linux, update to 1.3-9.amzn2 or later—this one needs your attention.

source: [aws/security-bulletin]

also that day:

Tuesday, September 8, 2026

OpenSearch Dashboards XSS Vulnerability Requires Urgent Patching

OpenSearch Dashboards has a stored cross-site scripting (XSS) flaw in its Vega expression function that lets authenticated users with dashboard write access inject malicious code affecting other users. This is a serious issue—if you're running v2.0.0 through v3.5.0, you need to upgrade to v2.19.5 or v3.6.0 immediately. AWS Managed and Serverless versions have separate patch schedules, so check your specific deployment.

source: [aws/security-bulletin]

also that day: