LIVE · cybersecurity feed
Live wire
vendor

Amazon

16 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical3
High12
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-137639.8criticalapplication load balancerInconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow r68d ago
CVE-2026-137629.8criticalcloudfrontInconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors68d ago
CVE-2026-182459criticalamplify codegen uiImproper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote aut37d ago
CVE-2026-772348.8highfreertosImproper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports t15d ago
CVE-2026-105918.8highkiro ideInsufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow95d ago
CVE-2026-189538.6highaws transform mcp serverImproper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transfo31d ago
CVE-2026-92557.8highkiro cliMissing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker 106d ago
CVE-2026-186567.8highkiro ideAn uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthentic32d ago
CVE-2026-186577.8highkiro cliAn uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthentica32d ago
CVE-2026-142657.5highadvanced jdbc wrapperDeserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 366d ago
CVE-2026-181407.5highaws-smithy-jsonUncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the 37d ago
CVE-2026-42697.5highbedrock agentcore starter toolkitA missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a rem173d ago
CVE-2026-772357.3highfreertosMissing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow 15d ago
CVE-2026-772367.3highfreertosMissing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local us15d ago
CVE-2026-818387.1highdiagram-as-codeA relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.9d ago
CVE-2026-42705.5mediumaws api mcp serverImproper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server version173d ago

Filter the full tracker by Amazon

Our coverage of Amazon

ai

Twitch wants your content for Amazon AI training. Here’s how to opt out

Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.

vulnerability

Amazon Q VS Extension Flaw Leads to Cloud Credential Theft

Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk.