Vulnerabilities in AWS

140 results
Vexday analysis

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2026-89332MEDIUMKiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace ConfigurationEPSS 0.2%CVE-2025-14760MEDIUMMissing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.2%CVE-2025-8069HIGHLocal Privilege Escalation Vulnerability in AWS Client VPN Windows ClientEPSS 0.2%CVE-2026-13769MEDIUMOverly permissive File Permissions in AWS CLIEPSS 0.2%CVE-2026-5429HIGHKiro IDE Webview Cross-Site Scripting via Workspace Color ThemeEPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2026-81838MEDIUMZip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)EPSS 0.1%CVE-2026-89065MEDIUMRelative path traversal in the generated file manifest cleanup component in projenEPSS 0.1%CVE-2026-4270MEDIUMAWS API MCP File Access Restriction BypassEPSS 0.1%CVE-2026-85788MEDIUMIncomplete list of disallowed inputs in awslabs mysql-mcp-serverEPSS 0.1%CVE-2026-11931MEDIUMInsecure Permissions on Authentication Token Cache File in Kiro IDEEPSS 0.1%CVE-2026-85028HIGHCreation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development KitEPSS 0.1%CVE-2026-9255HIGHTool Execution Without Authorization via Piped Stdin in Kiro CLIEPSS 0.1%CVE-2025-14763MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2026-18954MEDIUMIncorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP ServerEPSS 0.1%CVE-2025-14764MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introdEPSS 0.1%CVE-2025-14759MEDIUMMissing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to intrEPSS 0.1%CVE-2026-10584HIGHHTTPS Fallback to HTTP in Graph ExplorerEPSS 0.1%CVE-2026-6550MEDIUMKey commitment policy bypass via shared key cache in AWS Encryption SDK for PythonEPSS 0.1%CVE-2026-94450HIGHPotential denial of service when configured to send Retry packets in s2n-quicEPSS