Amazon's vulnerability profile spans a moderately broad portfolio that includes embedded operating systems, cloud infrastructure components, and open-source projects such as FreeRTOS, Fire OS, OpenSearch, and the TLS library Tough, reflecting the vendor's footprint across both consumer devices and enterprise cloud services. Vulnerabilities affecting the vendor carry a meaningful share of serious severity outcomes and cluster around command-injection and argument-injection flaws, certificate-validation weaknesses, and information-disclosure conditions that arise in the intersection of embedded firmware, network services, and cryptographic validation logic. The exposure across FreeRTOS and related embedded platforms is particularly relevant to defenders managing IoT and constrained-device deployments, while cloud-infrastructure and open-source disclosures affect a broader audience of AWS users and downstream dependents. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amazon over time
Of all the CVEs published by Amazon as a CNA, 43.3% affect products that Amazon develops as a vendor.
Of all the CVEs published that affect products developed by Amazon, 28.2% are self-published by Amazon as a CNA.
Signals from CVEs in this vendor scope (195 CVEs).
195 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2026-13763CRITICAL Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via cr | Jun 29, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-13762CRITICAL Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 | Jun 29, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-14265HIGH Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the s | Jul 1, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-10591HIGH Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via c | Jun 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-35561CRITICAL Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or | Apr 3, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-5707HIGH Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote | Apr 6, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-5708HIGH Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticat | Apr 6, 2026 | 8.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (195 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amazon.
Media articles that mention a CVE ID that affects a product developed by Amazon — matched by CVE ID, not by vendor name.