Latest Bulletins Read our latest security bulletins here.
- CVE-2026-96883 – Type confusion in AWS pgcollection allows remote code executionby aws@amazon.com on September 24, 2026 at 7:17 pm
Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection’s type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum’s representation, allowing an authenticated database user to crash the PostgreSQL backend or execute arbitrary code. Impacted versions: pgcollection v2.0.0 through v2.1.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. View article
- Issues with AWS Research and Engineering Studio (RES)by aws@amazon.com on September 24, 2026 at 5:49 pm
- CVE-2026-5429 – Kiro IDE Webview Cross-Site Scripting via Workspace Color Themeby aws@amazon.com on September 24, 2026 at 5:49 pm
- Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912by aws@amazon.com on September 24, 2026 at 5:49 pm
- CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWSby aws@amazon.com on September 24, 2026 at 5:49 pm
- CVE-2026-6550 – Key commitment policy bypass via shared key cache in AWS Encryption SDK for Pythonby aws@amazon.com on September 24, 2026 at 5:49 pm
- Issues with Amazon Athena ODBC Driverby aws@amazon.com on September 24, 2026 at 5:49 pm
- CVE-2026-5747 – Out-of-bounds Write in Firecracker virtio-pci Transportby aws@amazon.com on September 24, 2026 at 5:49 pm
- CVE-2026-6437 – Mount Option Injection in Amazon EFS CSI Driverby aws@amazon.com on September 24, 2026 at 5:49 pm
We are an ethical website cyber security team and we perform security assessments to protect our clients.




