bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-14265

show all
Wednesday, July 1, 2026

AWS Advanced JDBC Wrapper: Critical Deserialization Vulnerability in RemoteQueryCachePlugin

AWS Advanced JDBC Wrapper versions 3.3.0 through 4.0.0 have a nasty deserialization flaw (CVE-2026-14265) in RemoteQueryCachePlugin. If you've got this plugin enabled, an attacker with cache write access can inject malicious Java objects that execute arbitrary code on your app server. Update immediately if you're running affected versions—this one requires action.

> source: aws.amazon.com