bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, July 31, 2026

Critical RCE Vulnerability Found in OpenSearch Dashboards TSVB Plugin

OpenSearch Dashboards TSVB Plugin has a nasty remote code execution flaw (CVE-2026-18420) via prototype pollution. This is a serious one—you'll want to patch ASAP if you're running this. Check AWS Security Bulletin 2026-068 for the full details and fix.

source: [aws/security-bulletin]