Vulnerabilidades en AWS

140 resultados
Análisis Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2026-87912MEDIUMMissing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecopsEPSS 0.2%CVE-2026-87913MEDIUMMissing S3 bucket ownership verification in the AWS Security Agent MCP serverEPSS 0.2%CVE-2026-7426MEDIUMOut-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-6967HIGHMissing Delegated Metadata Validation in awslabs/toughEPSS 0.2%CVE-2025-13524MEDIUMImproper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call pEPSS 0.2%CVE-2026-4269MEDIUMImproper S3 ownership verification in Bedrock AgentCore Starter ToolkitEPSS 0.2%CVE-2026-22611LOWAWS SDK for .NET V4 adopted defense in depth enhancement for region parameter valueEPSS 0.2%CVE-2026-7425MEDIUMOut-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-16584HIGHAWS API MCP Server Security Policy Bypass via Startup FailureEPSS 0.2%CVE-2026-7424HIGHInteger Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-7423MEDIUMInteger Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-1386MEDIUMArbitrary Host File Overwrite via Symlink in Firecracker JailerEPSS 0.2%CVE-2025-11462CRITICALLocal Privilege Escalation Vulnerability in AWS Client VPN macOS ClientEPSS 0.2%CVE-2025-14761MEDIUMMissing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that EPSS 0.2%CVE-2026-18953MEDIUMImproper limitation of a pathname to a restricted directory in aws-transform-mcp-serverEPSS 0.2%CVE-2026-5747HIGHOut-of-bounds Write in Firecracker virtio-pci TransportEPSS 0.2%CVE-2025-14762MEDIUMMissing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK thatEPSS 0.2%CVE-2026-4295HIGHArbitrary code execution via crafted project files in Kiro IDEEPSS 0.2%CVE-2026-16317HIGHSilent Drop of TLS 1.3 Encrypted Records in s2n-tlsEPSS 0.2%CVE-2026-7422HIGHMAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet ProcessingEPSS 0.2%