// AWSHIGH
AWS Bedrock AgentCore InvokeHarness API (CVE-2026-18830, CVSS 8.6) allows authenticated remote attackers to bypass model authorization and invoke tools directly. AWS patched the managed service on July 31, 2026, but declined to issue a code fix for the underlying Strands Python SDK, leaving standalone deployments vulnerable to model-skipping attacks via caller-supplied tool-use blocks.
// Get alerts for AWS