<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Fargate on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/fargate/</link><description>Recent content in Fargate on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 19 Jun 2026 00:29:27 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/fargate/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS containerd CRI Flaws: CVE-2026-50195 &amp; More</title><link>https://zxcloudsecurity.co.uk/posts/aws-containerd-cri-vulnerabilities-cve-2026-50195-cve-2026-53488-eks-ecs-fargate/</link><pubDate>Fri, 19 Jun 2026 00:29:27 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-containerd-cri-vulnerabilities-cve-2026-50195-cve-2026-53488-eks-ecs-fargate/</guid><description>Five containerd CRI plugin vulnerabilities (CVE-2026-50195 and others) affect EKS, ECS, Fargate and more. Patch immediately to prevent host compromise.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/">AWS Security Bulletins</a></p>
<hr>
<p>AWS has identified five vulnerabilities in containerd&rsquo;s Container Runtime Interface (CRI) plugin affecting versions 1.7 through 2.3, impacting managed services including EKS, ECS, Fargate, Bottlerocket, and Amazon Linux. The flaws range from arbitrary host file reads and command execution via image labels, to container checkpoint abuse and a runtime denial-of-service. Exploitation could allow a malicious container image or checkpoint to compromise host systems or disrupt container workloads.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your EKS, ECS, and Fargate environments for exposure and apply AWS-provided patches or updated AMIs/node images immediately; also restrict who can push container images or initiate checkpoint restores, as several CVEs are exploitable via crafted images or checkpoint archives.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/">Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262</a></p>
]]></content:encoded></item></channel></rss>