bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: FSx

show all
Thursday, August 20, 2026

Critical Command Injection in Amazon ECS Agent for Windows

Amazon ECS Agent versions 1.47.0–1.102.2 have a nasty command injection vulnerability (CVE-2026-7461) when mounting FSx for Windows File Server volumes. An attacker can execute arbitrary code with SYSTEM privileges by crafting malicious credentials in task definitions. If you're running Windows ECS tasks with FSx volumes, you need to update immediately—this one's serious.

source: [aws/security-bulletin]