Aws
112 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.
Aws CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-12 | 3 | 0 |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | 9 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | 7 | 0 |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | 8 | 0 |
| 2026-04 | 18 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | 12 | 0 |
| 2026-07 | 19 | 0 |
| 2026-08 | 18 | 0 |
| 2026-09 | 18 | 0 |
Products
The products that kept showing up in Aws's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Aws.
- CVE-2026-96883Type confusion in AWS pgcollection allows remote code execution8.8
- CVE-2026-94450Potential denial of service when configured to send Retry packets in s2n-quic7.5
- CVE-2026-92943Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python8.1
- CVE-2026-86831Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS8.7
- CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center7.2
- CVE-2026-89332Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration5.5
- CVE-2026-89090Denial of service in the event stream header decoder in AWS SDK for Go v25.9
- CVE-2026-18061Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin5.9
- CVE-2026-89066OS command injection in the task synthesis component in projen7.8
- CVE-2026-89065Relative path traversal in the generated file manifest cleanup component in projen7.1
- CVE-2026-89049Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent9.9
- CVE-2026-87913Missing S3 bucket ownership verification in the AWS Security Agent MCP server5.9
- CVE-2026-87912Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops5.9
- CVE-2026-87911Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server9.6
- CVE-2026-85788Incomplete list of disallowed inputs in awslabs mysql-mcp-server5.5
The record
- Peak rank
- #50 in Apr 2026
- Busiest month shown
- Jul 2026, 19 CVEs
- Months with a KEV entry
- 0 since Dec 2022
- Monthly snapshots
- 9 since 2022