Amazon patches AgentCore flaws exposing AWS credentials
Amazon Web Services has patched two high-severity vulnerabilities in the Python software development kit for Amazon Bedrock AgentCore that could allow attackers to execute arbitrary commands inside Code Interpreter sandboxes and obtain temporary AWS credentials attached to customer execution roles. The flaws, tracked as CVE-2026-12530 and CVE-2026-16796, affected the SDK’s install_packages()…
We haven't written up this one. Arabian Post has the full story — the link below goes straight to it.