The Server Was Up. Its Security Policy Wasn’t.
What CVE-2026-16584 in the AWS API MCP Server taught me about MCP security, fail-open systems, and the controls we place between AI agents and real infrastructure. On July 23, 2026, AWS published a security advisory for a vulnerability I reported in the AWS API MCP Server. It was assigned CVE-2026-16584 , rated High, and given a CVSS v4.0 score of 7.3. My name appears in the acknowledgement as…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.