CVE-2026-83551 in AWS SageMaker Python SDK before v3.11.0 and v2.256.0 stores HMAC signing keys in cleartext within pipeline decorator components. Authenticated remote users can extract keys from DescribePipeline API responses and forge valid signatures for malicious function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.
AWS
Amazon Web Services — IAM, EC2, S3, and the rest.
Recent threats
CVE-2026-83497 is a high-severity vulnerability (CVSS 8.8) in the OpenSearch SQL plugin affecting AWS OpenSearch. Unrestricted deserialization of untrusted data in the cursor pagination component allows remote authenticated users with basic read/search permissions to execute arbitrary code on the server via a crafted cursor parameter.
AWS patched a widespread input validation flaw across seven SDKs (Python, Ruby, Go, Java, Node.js, PHP, .NET) that allowed attackers to hijack region parameters in hostnames and redirect API calls to attacker-controlled servers. The flaw particularly affects AssumeRoleWithWebIdentity calls, leaking plaintext bearer tokens and AWS credentials from EKS workloads, Cognito applications, and OIDC integrations. Discovered by Pi Inc., the vulnerability was reported October 2025 and patched by January 2026; only the .NET SDK received a CVE (CVE-2026-22611, rated 3.7/10).
A critical SSRF vulnerability (CVE-2026-64849) in MLflow is being actively exploited to steal cloud credentials from AWS, GCP, and Azure environments. Unauthenticated attackers craft malicious webhook payloads to force MLflow servers to access cloud metadata endpoints, exfiltrating sensitive credentials and tokens. Multiple organizations across technology, finance, healthcare, and government sectors have confirmed compromise. CISA has listed the vulnerability in its Known Exploited Vulnerabilities catalog. Remediation requires immediate upgrade to MLflow 3.15.0 and isolation of MLflow servers from public internet access.
A 153GB archive of stolen credentials from the LiteLLM AI framework breach exposed access credentials for 2,488 corporate domains, including AWS, Samsung, and Cisco. The compromised credentials originated from a breach of the LiteLLM open-source AI framework and were publicly surfaced in August 2026. Organizations using AWS should audit access logs and rotate exposed credentials.
AWS Bedrock AgentCore InvokeHarness API (CVE-2026-18830, CVSS 8.6) allows authenticated remote attackers to bypass model authorization and invoke tools directly. AWS patched the managed service on July 31, 2026, but declined to issue a code fix for the underlying Strands Python SDK, leaving standalone deployments vulnerable to model-skipping attacks via caller-supplied tool-use blocks.
Aryon Security research reveals 'ShutterGap,' a cloud-security blind spot affecting millions of AWS resources. RDS snapshots, DocumentDB snapshots, AMIs, and SSM documents are being briefly exposed publicly before removal, often within minutes. Security tools relying on periodic scans miss these short-lived exposures, while attackers can discover and copy data in seconds. 20% of exposed RDS snapshots appear and vanish in under two minutes, enabling rapid data exfiltration before detection.
AWS disclosed CVE-2026-15746, an SSRF vulnerability in the strands-agents-tools package (an open-source Python SDK for building AI agents). The elasticsearch_memory tool allows large language models to control connection parameters, enabling a crafted prompt to exfiltrate the operator's Elasticsearch API key to an attacker-controlled server. AWS recommends upgrading to version 0.7.0 or later and rotating all ELASTICSEARCH_API_KEY credentials as a precautionary measure.
CISA disclosed an internal security incident in which AWS GovCloud administrator credentials were exposed in a public GitHub repository maintained by a Nightwing contractor since November 2025. The repository contained Infrastructure as Code, build automation scripts, and plaintext admin credentials for three AWS GovCloud servers and internal CISA systems. Discovery occurred May 15, 2026 via external reporting; forensic analysis found no evidence the leaked credentials were used outside CISA environments, and no customer or mission data was compromised. CISA remediated by taking the repository offline, rotating credentials across all affected environments, and implementing repository upload controls and secrets management safeguards.
An AWS customer's LiteLLM-Proxy EC2 instance, functioning as an AI gateway to Amazon Bedrock, was compromised on June 12, 2026 via brute-force attacks against an exposed SSH port (0.0.0.0/0). Attackers deployed XMRig cryptomining malware and established persistence through the instance's privileged IAM role. Suspicious IAM activity detected a day later suggested possible credential misuse targeting Amazon Bedrock services. Darktrace's managed threat detection alerted the customer.
A lone attacker breached an AWS customer's cloud environment in 72 hours by exploiting AI workflows, chaining cloud configuration weaknesses, and using stolen credentials. The attacker accessed data and attempted extortion against the compromised Amazon customer.
Two high-severity vulnerabilities (CVE-2026-12957, CVE-2026-12958) in Amazon Q Developer Extension for VS Code and other IDEs allowed remote code execution and AWS credential theft when developers opened malicious repositories containing an `.amazonq/mcp.json` file. The extension auto-loaded MCP server configurations without user consent, enabling attackers to exfiltrate AWS credentials, API keys, and SSH agent sockets. Patches available in Language Servers for AWS 1.69.0 and corresponding IDE extensions.
- Amazon Q Vulnerability Let Attackers Execute Code and Access Sen(opens in a new tab)
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repos(opens in a new tab)
- Amazon Q Developer Vulnerability Allows Code Execution via Malic(opens in a new tab)
- Amazon Q Vulnerability Highlights the Growing Risk of AI Assiste(opens in a new tab)
- Amazon Q Vulnerability Let Attackers Execute Code and Access Sen(opens in a new tab)
- Amazon Q Flaw Enabled Cloud Credential Theft Through Malicious R(opens in a new tab)
Unit 42 researchers documented active attack techniques where threat actors disable or manipulate AWS CloudTrail logging to evade detection. Attackers can invoke the CloudTrail StopLogging API, delete log storage destinations, manipulate KMS encryption keys to render logs inaccessible, or redirect logs to attacker-controlled environments for persistent visibility. Organizations should enforce strict access controls on logging resources and leverage immutable log features.
A campaign tracked under Langflow vulnerability CVE-2026-33017 is being actively exploited to steal AWS access keys from compromised Langflow instances and enlist victim systems as workers in a NATS-based botnet. The flaw resides in Langflow, a third-party open-source AI workflow tool, but exposed deployments commonly hold AWS credentials used to wire Langflow into cloud services, making AWS customers running Langflow the primary loot target. Reporting describes ongoing in-the-wild exploitation of internet-exposed Langflow servers, with attackers exfiltrating cloud keys and deploying secondary payloads. AWS customers operating Langflow should patch to the fixed version, audit IAM credentials configured in Langflow flows, rotate any keys that may have been exposed, and review CloudTrail for anomalous activity originating from those keys. This is distinct from prior AWS-related advisories tracked in recent alerts.
AI observability startup Braintrust disclosed that an attacker gained unauthorized access to one of its AWS accounts, potentially exposing customer secrets used to connect Braintrust to cloud-based AI providers. The company detected suspicious activity on May 4, 2026, locked down the affected account, rotated internal credentials, restricted access to related systems, and engaged incident response experts. Braintrust has confirmed impact to one customer and is investigating suspicious AI-provider usage spikes reported by three additional customers, though it says broader exposure has not been identified. All organization administrators with stored AI provider keys were notified, and customers are urged to rotate any org-level AI provider keys used with Braintrust as a precaution. The incident illustrates AI supply chain risk, since stolen API keys can let attackers abuse downstream AI services while appearing as legitimate users.
Wasabi Protocol disclosed a security breach in which attackers exploited a vulnerability in its AWS infrastructure to obtain private keys controlling its smart contracts, resulting in the theft of approximately $5.7 million on April 30, 2026. About $4.8 million was taken from user funds and $900,000 from the project treasury across EVM vaults on Ethereum, Base, Blast, and Berachain; Solana deployments and Prop AMM were not affected. Wasabi states the vulnerability has been contained and unaffected vaults resumed withdrawals on May 2, with ZeroShadow engaged to trace the stolen funds. The reported issue concerns Wasabi's use of AWS rather than a confirmed flaw in AWS itself, and no AWS-side advisory has been published. No definitive user compensation plan has been announced.
Red Hat has disclosed a Linux kernel local privilege escalation vulnerability dubbed "Dirty Frag" (pending CVE, tracked as RHSB-2026-003) that affects Red Hat OpenShift Service on AWS (ROSA Classic) and ROSA with Hosted Control Plane, alongside other OpenShift variants. The flaw resides in kernel code paths reachable via the esp4, esp6, and rxrpc modules, enabling a local attacker to escalate privileges on cluster nodes. Patched kernels will be delivered via OpenShift z-stream updates through the OpenShift Update Service. As an interim mitigation, Red Hat recommends blacklisting the affected kernel modules, which does not require node reboots but will break workloads that depend on IPsec or related functionality. ROSA operators should apply the mitigation now and track z-stream availability for a permanent fix.
A command injection vulnerability has been disclosed affecting Amazon ECS on Windows, tracked publicly without a formal CVE identifier and rated medium severity. The flaw reportedly allows an attacker to inject operating system commands through the ECS Windows component, potentially leading to unauthorized command execution within affected container environments. No public reports of active exploitation have been identified, and AWS customers running ECS on Windows should review AWS security bulletins and apply mitigations or updates as they become available. Other sources reviewed did not contain AWS-specific security events and were excluded.
AWS published security bulletin AWS-2026-026 covering CVE-2026-31431. The bulletin appears on the official AWS security bulletins feed, indicating an advisory affecting an AWS service or component, though specific technical details, affected services, and remediation guidance were not retrievable from the provided excerpt. Customers should consult the AWS bulletin directly to determine impact and required action. The other sources referenced (Apache HTTP/2 RCE, Q1 2026 vulnerability landscape, and a CVE refresh-planning article) are not AWS-specific and were excluded.