Disclosure summary
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is so
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Latest Bulletins · RSS-41c7df7bffb3ef5a4c79b40971ab0032956
Open original source · Updated Sep 10, 2026
CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- aws.amazon.com — Publisher advisory
PUBLISHED 2026-09-10T14:44:24-04:00
MODIFIED 2026-09-10T14:44:24-04:00
INGESTED 2026-10-08T12:10:48-04:00