CVE-2026-18733: Prompt Injection Bypass in AWS Strands Agent
CVE-2026-18733 lets attackers bypass the shell tool consent gate in Strands Agents Tools via prompt injection, enabling unapproved OS command execution.
Daily advisories covering CVEs and security issues affecting AWS-native services: IAM, S3, EC2, EKS, ECS, Lambda, RDS, CloudTrail, KMS, and the broader AWS service catalogue. Each advisory includes severity, attack vector, and a practical recommendation for architects running workloads in AWS.
Looking for deeper context? Our practitioner guides cover the AWS security controls that matter most:
CVE-2026-18733 lets attackers bypass the shell tool consent gate in Strands Agents Tools via prompt injection, enabling unapproved OS command execution.
CVE-2026-18420 enables remote code execution via prototype pollution in the OpenSearch Dashboards TSVB plugin. AWS customers should patch immediately.
CVE-2026-14904 in AWS Research and Engineering Studio lets authenticated users read root-accessible files via a symlink attack. Patch immediately.
Five containerd CRI plugin vulnerabilities (CVE-2026-50195 and others) affect EKS, ECS, Fargate and more. Patch immediately to prevent host compromise.
CVE-2026-12043 is a heap double-free in AWS Common Runtime aws-c-http that could allow a malicious server to achieve remote code execution on SDK clients.
AWS SDK for C++ versions ≤1.11.861 contain out-of-bounds read/write flaws in the Base64 decoder. Learn the impact and remediation steps.
CVE-2026-19311 lets authenticated OpenSearch users read, modify or delete arbitrary index data. Patch to 2.19.6, 3.8.0 or AWS R20260428-P3 now.
Learn how to identify and remediate over-permissioned Amazon S3 bucket policies and ACLs to prevent unauthorised data exposure in your AWS environment.
CVE-2026-19111 is an IDOR flaw in AWS Strands Agents Tools allowing attackers to access or tamper with other tenants' AI agent memories via prompt injectio
CVE-2026-18954 allows authenticated clients to bypass read-only mode in Amazon DocumentDB MCP Server via $out/$merge pipeline stages. Patch to v1.0.12.
CVE-2026-18953 affects AWS Transform MCP Server v0.1.0–0.1.4. A path traversal flaw allows arbitrary file writes and potential local code execution. Patch
AWS Kiro IDE and CLI for Windows are vulnerable to arbitrary code execution via binary planting. Update to patched versions immediately.
CVE-2026-18830 allowed authenticated users to bypass model security controls in Amazon Bedrock AgentCore's InvokeHarness API. Patched 31 July 2026.
AWS CLI EMR SSH helper commands disable host key verification, enabling MITM attacks. Affects CLI v1 ≤1.45.27 and v2 ≤2.35.2. Patch immediately.
CVE-2026-18655 in AWS Amazon MQ MCP Server (≤2.0.23) lets unauthenticated attackers steal RabbitMQ credentials via prompt injection. Patch to 2.0.24 now.
CVE-2026-18394 exposes credentials in Strands Agents Tools http_request tool via proxy manipulation. Upgrade to v0.8.2 or later immediately.
AWS confirms an incomplete fix for CVE-2025-4318, a code injection flaw in @aws-amplify/codegen-ui-react. Update to the latest patched version immediately.
CVE-2026-18140 allows unauthenticated remote denial of service in smithy-rs generated servers via uncontrolled recursion in aws-smithy-json.
Amazon links North Korean state hackers to NPM library compromises. Learn what cloud security architects should do to protect their software supply chains.
Learn how to protect Amazon Linux environments from supply chain attacks targeting npm and PyPI packages during their riskiest publication window.
CVE-2026-16796 affects AWS Bedrock AgentCore Python SDK versions below 1.18.1, enabling authenticated users to run arbitrary commands via install_packages(
CVE-2026-16756 in aws-smithy-http-server ≤0.66.4 allows unauthenticated Slowloris DoS attacks. Learn the impact and how to remediate.
CVE-2026-16584 allows security policy bypass in AWS API MCP Server (0.2.13–1.3.47) when startup fails. Update to 1.3.47 or enable fail-closed mode now.
Two s2n-tls vulnerabilities: a TLS 1.3 AEAD bypass enabling silent record drops and a QUIC memory leak via HelloRetryRequest. AWS patch required.
CVE-2026-15957 in smithy-rs allows unauthenticated remote DoS via stack exhaustion in JSON, CBOR, and XML deserialisers. Update aws-sdk-rust to release-202
CVE-2026-15415 affects aws-healthomics-mcp-server <=0.0.35, enabling arbitrary file writes via path traversal in workflow linting tools. Patch now.
CVE-2026-12283 affects the AWS Athena Synapse Connector (2022–2026), allowing crafted table names to expose unintended data via federated queries.
CVE-2026-15895 is an OS command injection flaw in AWS jsii-diff. Versions before 1.131.0 allow shell command execution via crafted CLI arguments.
CVE-2026-15737 exposes raw AI prompts and responses via CloudWatch Logs in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0.
CVE-2026-15746 exposes Elasticsearch API keys via SSRF in AWS Strands Agents Tools. Upgrade to v0.7.0+ and rotate credentials immediately.
CVE-2026-15738 in AWS Load Balancer Controller allows cross-namespace traffic interception via incorrect HTTPRoute/GRPCRoute priority ordering on shared AL
CVE-2026-15643 is an SSRF flaw in AWS HealthLake MCP Server before 0.0.14 that lets authenticated attackers steal AWS temporary credentials via a crafted p
CVE-2026-14471 affects AWS mcp-gateway-registry v1.0.3–1.0.12, enabling authenticated SQL injection that exposes API keys and allows data tampering.
Learn how AWS Cedar enforces least-privilege authorisation across multi-agent AI chains, preventing silent privilege escalation in agentic systems.
CVE-2026-14265 enables remote code execution via unsafe deserialization in the AWS Advanced JDBC Wrapper RemoteQueryCachePlugin. Versions 3.3.0–4.0.0 affec
CVE-2026-13760 is an OS command injection flaw in AWS CDK's Docker bundling pipeline affecting aws-cdk-lib < 2.260.0. Upgrade immediately.
CVE-2026-13769 in AWS CLI exposes credentials as world-readable on Unix systems. Affects CLI v1 ≤1.44.77 and v2 ≤2.34.28. Patch now.
AWS WAF HTTP/2 multi-frame inspection flaws (CVE-2026-13762, CVE-2026-13763) could allow WAF bypass on ALB. Action required for ALB deployments.
Two vulnerabilities in AWS Language Servers affect Amazon Q Developer IDE plugins. Learn the impact of CVE-2026-12957 and CVE-2026-12958 and how to remedia
CVE-2026-12530 in AWS Bedrock AgentCore Python SDK allows argument injection in install_packages(), enabling malicious PyPI redirects and sandbox file expo
CVE-2026-11931 exposes Kiro IDE authentication token cache files to local users via weak file permissions on macOS and Linux. Update to v0.11.133+.
CVE-2026-10584 causes Graph Explorer (v1.1.0–3.0.1) to silently fall back to HTTP, exposing Amazon Neptune data in cleartext. Upgrade to v3.0.1 now.
CVE-2026-10591 affects Kiro IDE versions below 0.11, allowing unauthenticated attackers to execute arbitrary commands via writes to sensitive IDE config pa
AWS Certificate Manager now supports ACME protocol for automated TLS certificate renewal, essential as CA/Browser Forum cuts max validity to 47 days by 202
Route Amazon Bedrock Guardrails violations to Security Lake to unify AI safety events with identity, network, and application security telemetry for incide
AWS outlines a security control framework for AI coding agents like Kiro and Claude Code, addressing risks from autonomous code generation at scale.
AWS Shield Advanced is adopting the new WAF Anti-DDoS managed rule group for HTTP flood protection. Here's what changes and how to prepare your setup.
Amazon releases July 2026 quarterly security updates for Corretto 8–26. Docker images now default to Amazon Linux 2023. Update Java workloads promptly.
Amazon GuardDuty AI Protection detects prompt injection, cost harvesting, and anomalous invocations targeting AWS Bedrock and SageMaker AI workloads.
Learn how AWS WAF Bot Control can authenticate legitimate AI agent traffic in multi-tenant environments like Amazon Bedrock AgentCore.
AWS is now a designated Critical Third Party to the UK financial sector. Learn what this means for cloud security architects in regulated financial firms.
AWS Security Hub now actively probes resources to confirm internet reachability across AWS and Azure, surfacing exposed ports and services beyond config-ba
AWS outlines the risk of system prompt leakage in generative AI apps and provides architectural mitigations for cloud security teams to reduce exposure.
AWS outlines how CISOs can lead post-quantum cryptography migrations across complex organisations, meeting global PQC mandates before quantum threats mater
Learn how to use Amazon Bedrock Projects and AWS Service Control Policies to centrally enforce zero data retention across all accounts using third-party AI
AWS Network Firewall now supports container attribute-based rules for EKS and ECS, enabling workload-level traffic control for AI/ML and containerised apps
Amazon GuardDuty Runtime Monitoring now detects sensitive file modifications on EC2, EKS, and ECS — covering persistence, privilege escalation, and defence
AWS IAM Identity Center now lets customer-managed apps retrieve temporary AWS credentials via trusted token issuers. Key governance and security implicatio
AWS CIRT's June 2026 Threat Technique Catalog update documents real-world attack patterns. Here's what cloud security architects need to review and act on.
AWS now supports resource-based policies and RCPs for Sign-In, letting you restrict Management Console and CLI access to trusted networks only.
Learn how to implement AWS egress controls to prevent data exfiltration from cloud workloads using VPC policies, SCPs, and Network Firewall.
Learn how attackers exploit dangling DNS records for subdomain takeover on AWS, and how to detect and prevent it using Route 53 and AWS security services.
Learn how to audit unused AWS KMS keys, reduce costs, meet compliance requirements, and prevent accidental key deletions across multi-account environments.
Learn how AWS Bedrock AgentCore resource-based policies enforce tenant isolation, cross-account access controls, and VPC-only traffic for SaaS AI workloads
Amazon Cognito now supports multi-Region replication for user pools, improving authentication resilience and enabling near real-time failover across AWS Re
AWS adds a new Cognito Lambda trigger enabling custom logic during federated sign-in via SAML, OIDC, and social providers. Here's what architects need to k
AWS IoT Device Management adds MQTT session and socket data to its connectivity API. Learn the IAM controls and security implications for IoT fleets.
AWS IoT Device Management adds MQTT session data to its connectivity status API, with indefinite retention and IAM-controlled socket-level access for IoT f
AWS Step Functions integrates with Amazon Bedrock AgentCore to embed AI reasoning steps in workflows. Key security considerations for architects.
OpenAI GPT-5.4 is now available on Amazon Bedrock in AWS GovCloud (US-West), offering isolated inference for government and regulated-industry workloads.
AWS ARC Region switch gains Aurora serverless, provisioned scaling, and Neptune failover blocks, automating multi-region DB recovery and reducing RTO.
Amazon SageMaker Unified Studio now supports 12 languages. No security impact — a usability update for global teams with no changes to IAM or access contro
AWS Config now supports 9 new resource types across Bedrock and SageMaker, improving compliance visibility for AI/ML workloads in your AWS environment.
Amazon ECS Managed Instances now supports Trainium and Inferentia AI accelerators. Learn the security implications for cloud architects running ML workload
AWS IoT Core now offers Ping and Connection.AuthNError CloudWatch log types to help detect connectivity failures and authentication errors across IoT fleet
AWS Config now supports internal service linked rules, letting AWS services like Security Hub CSPM run independent rule evaluations at no extra cost to cus
AWS Deadline Cloud now supports persistent EBS volumes for Service-Managed Fleets. Learn the security implications for cloud architects managing rendering
SageMaker Studio now auto-attaches an IAM policy for model customisation. Security architects should audit this managed policy against least-privilege prin
Get daily cloud security advisories delivered to your inbox.
Free. No spam. Unsubscribe anytime. View subscription options