bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Security Update

show all
Thursday, July 23, 2026

AWS Bedrock AgentCore Python SDK Vulnerability Requires Immediate Update

AWS Bedrock AgentCore Python SDK versions below 1.18.1 contain CVE-2026-16796, a command injection flaw in the install_packages() method that could let authenticated users execute arbitrary commands in the Code Interpreter sandbox through crafted package names. If you're using bedrock-agentcore, update to version 1.18.1 or later right away—this one needs your attention.

> source: aws.amazon.com

Friday, July 17, 2026

AWS Athena Synapse Connector Vulnerability Requires Immediate Patching

AWS Athena's Synapse connector has a critical flaw (CVE-2026-12283) where specially crafted table names can leak unintended data when queried. If you're running versions v2022.20.1 through v2026.19.1, you need to update immediately—this affects anyone using Athena Query Federation with Azure Synapse. The vulnerability requires attacker access to your Synapse account, but the impact is serious enough that AWS flagged it as Important.

> source: aws.amazon.com

Tuesday, June 23, 2026

Critical Security Fixes for Amazon Q Developer Language Servers

Amazon Q Developer IDE plugins (VS Code, JetBrains, Eclipse, Visual Studio) need urgent updates due to two vulnerabilities in Language Servers for AWS. CVE-2026-12957 allows malicious workspace configs to execute commands if you trust the workspace, while CVE-2026-12958 exploits symlink validation gaps. Update to Language Servers for AWS 1.69.0 or your IDE plugin's latest version immediately—user action is required.

> source: aws.amazon.com