CVE Tools

Aws

112 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.

Aws CVEs per month

Dec 2022 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Aws CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1230
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-0390
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1270
2026-01null or fewer
2026-02null or fewer
2026-0380
2026-04180
2026-05null or fewer
2026-06120
2026-07190
2026-08180
2026-09180

Products

The products that kept showing up in Aws's monthly top three, with their CVEs summed over those months.

  1. Tough72 months
  2. Freertos-plus-tcp51 month
  3. Amazon Opensearch Service42 months
  4. Aws-lc41 month
  5. Opensearch31 month
  6. Tuftool31 month
  7. Aws Serverless Application Model Command Line Interface21 month
  8. Aws-lc-fips21 month
  9. Aws-sdk-cpp21 month
  10. Kiro Ide21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Aws.

  1. CVE-2026-96883Type confusion in AWS pgcollection allows remote code execution8.8
  2. CVE-2026-94450Potential denial of service when configured to send Retry packets in s2n-quic7.5
  3. CVE-2026-92943Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python8.1
  4. CVE-2026-86831Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS8.7
  5. CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center7.2
  6. CVE-2026-89332Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration5.5
  7. CVE-2026-89090Denial of service in the event stream header decoder in AWS SDK for Go v25.9
  8. CVE-2026-18061Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin5.9
  9. CVE-2026-89066OS command injection in the task synthesis component in projen7.8
  10. CVE-2026-89065Relative path traversal in the generated file manifest cleanup component in projen7.1
  11. CVE-2026-89049Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent9.9
  12. CVE-2026-87913Missing S3 bucket ownership verification in the AWS Security Agent MCP server5.9
  13. CVE-2026-87912Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops5.9
  14. CVE-2026-87911Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server9.6
  15. CVE-2026-85788Incomplete list of disallowed inputs in awslabs mysql-mcp-server5.5

The record

Peak rank
#50 in Apr 2026
Busiest month shown
Jul 2026, 19 CVEs
Months with a KEV entry
0 since Dec 2022
Monthly snapshots
9 since 2022
Aws's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store