Issues with Amazon Athena ODBC Driver
Update the Amazon Athena ODBC driver to version 2.1.0.0 to patch critical security vulnerabilities (CVE-2026-5485 through CVE-2026-35562) and ensure secure data access across your applications.
Machine-filtered, human-readable judgment for DevOps and Platform leaders.
Update the Amazon Athena ODBC driver to version 2.1.0.0 to patch critical security vulnerabilities (CVE-2026-5485 through CVE-2026-35562) and ensure secure data access across your applications.
Update Graph Explorer to version 3.0.1 to address CVE-2026-10584, ensuring HTTPS is properly enforced and sensitive data is not transmitted in cleartext.
Update the Harmonix on AWS deployment to version 0.4.2 or later to address the security vulnerability (CVE-2025-14503) and review IAM trust policies to restrict role assumption capabilities, particularly for the EKS environment provisioning role.
Update Firecracker to version v1.14.1 or v1.13.2 to address the security vulnerability CVE-2026-1386, ensuring that your deployments are secure and compliant with AWS security standards.
Update the core networking code to include the correctness patch against the Fragnesia vulnerability (CVE-2026-46300) to harden network protocol implementations and prevent potential exploits.
Update AWS Ops Wheel deployments to the latest version (PR #165) to address critical security vulnerabilities (CVE-2026-6911 and CVE-2026-6912) and restrict network access to API Gateway endpoints as a temporary workaround.
Update Amazon Aurora MySQL, Amazon RDS for MySQL, and Amazon RDS for MariaDB to the specified versions to address the CVE-2026-3494 vulnerability and ensure proper logging of SQL statements.
Update the AWS API MCP Server to version 1.3.9 to address the file access restriction bypass vulnerability (CVE-2026-4270) and ensure the security of your AWS infrastructure.
Update Kiro IDE to version 0.11 to address CVE-2026-10591 and prevent potential security breaches from arbitrary command execution.
Update AWS wrappers for Aurora PostgreSQL to the specified versions to address the privilege escalation vulnerability (CVE-2025-12967) and maintain secure database operations.
Update the AWS Client VPN client installations on Windows devices to version 5.2.2 to address the local privilege escalation vulnerability (CVE-2025-8069) and prevent potential security risks associated with arbitrary code execution during the installation process.
Update Amazon.IonDotnet to version 1.3.2 to address the infinite loop issue and prevent potential denial of service attacks.
Update the Amazon Redshift JDBC Driver to version 2.2.2 to address the unsafe class loading vulnerability (CVE-2026-8178) and prevent potential security breaches.
Update the rabbitmq-aws plugin to version 0.2.1 and rotate any secrets stored in files accessible to the RabbitMQ process to address the arbitrary file read vulnerability (CVE-2026-9133).
Update the ECS agent to version 1.97.1 or modify EC2 security groups to restrict access to the introspection server port (51678) to address the security vulnerability CVE-2025-9039.
Update your S3 Encryption Client libraries to the latest versions to resolve key commitment issues and protect against potential security threats, ensuring compatibility with existing and new encrypted data.
Update configurations for AWS CLI, SDK, and SSM Agent to follow AWS's guidelines, and monitor network traffic for unexpected IMDS endpoints to prevent impersonation issues.
Update AWS Research and Engineering Studio to version 2026.03 and apply patches to mitigate CVE-2026-5707, CVE-2026-5708, and CVE-2026-5709 vulnerabilities, ensuring secure session management and privilege controls.
Update Ion-C to version 1.1.4 to address the integer overflow vulnerability (CVE-2025-12829) and prevent potential data exposure.
Update the regular expressions for AWS CodeBuild webhook filters in your repositories to ensure they are properly scoped and configured to allow-listed identities only, and consider implementing additional security measures such as credential rotations and pull request build policies to enhance CI/CD security.
Update RES to version 2025.09 to address CVE-2025-12815, which allows viewing of unauthorized desktop session metadata and screenshots.
Update coreMQTT to version 5.0.1 to address the CVE-2026-8686 vulnerability and prevent potential crashes caused by malicious MQTT packets.
Update all affected AWS SDKs and libraries to their latest versions to address the CVE-2026-5190 vulnerability and ensure secure communication with event-stream services.
Update QnABot on AWS to version 7.3.0 to address CVE-2026-7191, which involves removing the static-eval dependency and replacing it with a custom expression evaluator to prevent sandbox bypass.
Update ECS Windows worker instances to the latest Amazon ECS-optimized Windows AMI with ECS agent version 1.103.0 to address the command injection vulnerability (CVE-2026-7461) and prevent potential code execution with SYSTEM privileges.
Patch macOS AWS ClientVPN to version 5.2.1 to resolve CVE-2025-11462, a local privilege escalation issue due to improper log validation, to prevent potential security breaches.
Update the Amazon WorkSpaces client for Linux to version 2025.0 to address the security vulnerability (CVE-2025-12779) and prevent unauthorized access to user workspaces.
Update Amazon Linux kernels to the latest versions and apply the provided mitigations to disable affected modules and prevent unauthorized privilege escalation through the 'Dirty Frag' vulnerabilities.
Update Kiro IDE to version 0.8.140 to address the critical security vulnerability CVE-2026-5429, ensuring that all forked or derivative code is patched to prevent potential cross-site scripting attacks.
Patch and discontinue the use of Amazon Cloud Cam devices due to the insecure device pairing vulnerability (CVE-2025-6031) and ensure no active deployments are using this end-of-life product.
Update the amazon-redshift-python-driver to version 2.1.14 to address the remote code execution vulnerability (CVE-2026-8838) and ensure all forked or derivative code is patched accordingly.
Update the Amazon Skylight Workspace Config Service to version 2.6.2034.0 to address the TOCTOU race condition vulnerability (CVE-2026-7791) and ensure system security by rebooting impacted WorkSpaces.
Update the SageMaker Python SDK to versions v3.2.0 or v2.256.0 to patch the HMAC configuration issue and to versions v3.1.1 or v2.256.0 to address the insecure TLS configuration, ensuring secure and compliant machine learning model deployments.
Update React to versions 19.0.1, 19.1.2, and 19.2.1, and Next.js to the latest patched versions to address the RCE vulnerability, and consider deploying a custom AWS WAF rule for added protection.
Update your CodeBuild configurations to disable automatic builds from untrusted contributors and rotate any compromised credentials to prevent unauthorized code modifications.
Update FreeRTOS-Plus-TCP to version V4.4.1 or V4.2.6 to address out-of-bounds read and write issues in the IPv6 Router Advertisement option parser, reducing the risk of network exploitation.
Update the Bedrock AgentCore Starter Toolkit to version v0.1.13 or greater to address the security vulnerability (CVE-2026-4269) and prevent potential code injection during the build process.
Update Amazon SageMaker Python SDK to versions v2.257.2 and v3.8.0 to address security vulnerabilities (CVE-2026-8596 and CVE-2026-8597) and rebuild models previously created with ModelBuilder using the updated SDK to remove the HMAC key from container environment variables.
Update Amazon Q Developer to version 1.24.0 or newer and Kiro to version 0.1.42 to address prompt injection vulnerabilities and enforce Human-in-the-Loop confirmations for critical commands.
Update the Amazon EFS CSI Driver to version v3.0.1 to address the mount option injection vulnerability (CVE-2026-6437) and ensure the security of your Kubernetes clusters using Amazon EFS.
Update Amazon EMR clusters to version 7.5 or higher to apply the security patch for CVE-2025-8904, which removes the vulnerable /tmp/ directory for storing Kerberos credentials, reducing the risk of privilege escalation.
Update applications using FreeRTOS-Plus-TCP to version 4.3.4 to address critical security vulnerabilities (CVE-2025-11616, CVE-2025-11617, CVE-2025-11618) and ensure system security.
Update Kiro CLI to version 1.28.0 and apply the --no-interactive flag when piping content from untrusted sources to prevent potential security breaches due to CVE-2026-9255.
Update your container management systems to the latest versions of runc (version 1.3.2-2) to address the security vulnerabilities. For Amazon ECS, ensure you are using the latest AMIs or perform a 'yum update -security'. For EKS, update your nodes to the patched AMIs or delete existing Fargate pods to use the patched runtime.
Update Amazon Braket SDK to version 1.117.0 and restrict S3 bucket policies to trusted principals to address CVE-2026-9291 and prevent potential security breaches from malicious job results.
Update AWS Encryption SDK for Python to versions 3.3.1 or 4.0.5 to address the key commitment policy bypass vulnerability (CVE-2026-6550) and ensure secure encryption practices.
Update Amazon Q Developer Extension for Visual Studio Code to version 1.85.0 to remove the security vulnerability identified in version 1.84.0 and prevent potential threats.
Update Graph Explorer to version 3.0.1 to address CVE-2026-10584, ensuring HTTPS is properly configured to prevent fallback to HTTP and cleartext transmission of sensitive information.
While deploying Model Context Protocol (MCP) servers in production, enterprises need fine-grained access control across servers, observability into which teams use which tools, security guarantees against data exfiltration, and centralized credential management, all at scale. Amazon Bedrock AgentCore Gateway sits between MCP servers and the clients that consume them, centralizing credential management, observability, and secure [โฆ]
Update your data integration pipelines to utilize the new CDC iterator position feature, which provides an iteratorDescription structure with an iteratorPosition field, to adapt polling frequency and lower CDC consumption costs while maintaining timely data processing.
Update your database deployment processes to include support for Db2 v12.1 and consider utilizing Db2 Community Edition for development and testing to reduce costs and simplify licensing concerns.
Configure new ElastiCache clusters with durability options to ensure data resilience without compromising performance, utilizing synchronous writes for zero data loss scenarios and asynchronous writes for microsecond latency requirements.
Update your EKS clusters to Kubernetes version 1.36 to take advantage of new features like User Namespaces and In-Place Pod-Level Resources Vertical Scaling, and ensure your infrastructure-as-code tools are configured to support the new version.
Update ElastiCache clusters to enable durability options, choosing between synchronous and asynchronous writes based on your application's requirements for data persistence and latency.
Update your AWS HealthOmics workflows to Nextflow v26.04 to benefit from the strict syntax parser, record types, workflow output summaries, and agent logging mode, which will reduce compute time and improve debugging efficiency.
Update your SQL Server migration strategy to include Amazon RDS for SQL Server BYOM, allowing you to leverage existing licenses and integrate with AWS License Manager for compliance tracking.
Configure the StartRun API to specify Nextflow engine versions (22.04, 23.10, 24.10, 25.10, 26.04) using the new engine-settings parameter, allowing for controlled environment testing and version management without modifying workflow source code.
If you manage DNS across multiple AWS accounts with Amazon Route 53 Profiles, achieving least-privilege access for each team can be challenging. Without fine-grained permissions, one team might inadvertently modify another teamโs resources leading to governance gaps, security risks, and slower adoption of centralized DNS management. The new fine-grained AWS Identity and Access Management (AWS [โฆ]
Amazon Cognito now offers multi-Region replication that automatically synchronizes user data, credentials, and pool configurations to a secondary AWS Region, enabling uninterrupted authentication during regional failovers without forced password resetsโplus new support for customer managed KMS keys for encryption control.
Introduction Private connectivity from AgentCore Gateway to your targets reduces compliance scope and simplifies auditing making it a common requirement in regulated environments. Whether your targets run inside an Amazon Virtual Private Cloud (Amazon VPC), across AWS accounts, in other AWS Regions, on-premises, or in multicloud environments, you need connectivity patterns that keep traffic off the public [โฆ]
Deploy the new HyperPod troubleshooting skills to leverage expert-level diagnostics and automated workflows for faster resolution of cluster issues, reducing manual effort and toil.
Asโฏpreviously announced, version 3 of the AWS SDK for .NETโฏentered maintenance mode on March 1, 2026. In alignment with our SDKs and Tools Maintenance Policy,โฏAWS SDK for .NET V3 has now reached end-of-support as of June 1, 2026. Starting June 1, 2026, there are no plans for further updates or releases for V3, including security fixes. [โฆ]
OpenAI frontier models GPT-5.5 and GPT-5.4, and Codex, the OpenAI coding agent, are now generally available on Amazon Bedrock. Deploy frontier models on Bedrock's high performance inference engine with built-in security, governance, and pay-per-token pricing.
Asโฏpreviously announced, version 4 of theโฏAWS Tools for PowerShellโฏentered maintenance mode on March 1, 2026. In accordance with ourโฏSDKs and Tools Maintenance Policy,โฏAWS Tools for PowerShell V4 has now reached end-of-support as of June 1, 2026. Starting June 1, 2026, there are no plans for further updates or releases for V4, including security fixes. Previously published releases should continue [โฆ]