bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Friday, July 17, 2026

AWS HealthOmics MCP Server Path Traversal Vulnerability – Update Required

AWS HealthOmics MCP Server versions 0.0.35 and earlier have a path traversal flaw (CVE-2026-15415) in workflow linters that could let attackers write files outside intended directories. If you're running aws-healthomics-mcp-server, upgrade to version 0.0.36 or later immediately. This affects the workflow_files input processing, so action is required if you use this service.

source: [aws/security-bulletin]

AWS Athena Synapse Connector Vulnerability Requires Immediate Patching

AWS Athena's Synapse connector has a critical flaw (CVE-2026-12283) where specially crafted table names can leak unintended data when queried. If you're running versions v2022.20.1 through v2026.19.1, you need to update immediately—this affects anyone using Athena Query Federation with Azure Synapse. The vulnerability requires attacker access to your Synapse account, but the impact is serious enough that AWS flagged it as Important.

source: [aws/security-bulletin]

Thursday, July 16, 2026

AWS jsii-diff Command Injection Vulnerability Requires Immediate Update

AWS jsii-diff, a CLI tool for comparing API differences between jsii assemblies, has a critical OS command injection flaw (CVE-2026-15895). Attackers can execute arbitrary shell commands through specially crafted command-line arguments. If you're running jsii-diff versions below 1.131.0, update immediately—this one's not optional, folks.

source: [aws/security-bulletin]

Bedrock AgentCore Python SDK Leaks Sensitive Data via OpenTelemetry Spans

AWS flagged CVE-2026-15737 in bedrock-agentcore versions 1.4.8 and 1.5.0—unfiltered user prompts and agent responses get logged to CloudWatch, exposing them to anyone with read access. **Action required**: upgrade immediately if you're running affected versions. Local authenticated users could snoop on your sensitive AI interactions through OpenTelemetry span attributes.

source: [aws/security-bulletin]

also that day:

Wednesday, July 15, 2026

Strands Agents Tools: Critical Credential Leak in elasticsearch_memory

Strands Agents' elasticsearch_memory tool (versions < 0.7.0) has a nasty SSRF vulnerability that can leak your Elasticsearch API keys. The LLM can control connection parameters and trick the tool into sending credentials to attacker-controlled servers. If you're running affected versions, update immediately—this one requires action.

source: [aws/security-bulletin]

also that day: