All Articles
AWS closes critical security vulnerabilities in Bedrock AgentCore
Markets3 min read

AWS closes critical security vulnerabilities in Bedrock AgentCore

By Redaktion aktie.com

This article was created with the help of artificial intelligence.

Key Takeaways

  • Amazon Web Services has closed multiple critical security vulnerabilities in its AI service Bedrock AgentCore that could have enabled attackers to access all AgentCore agents within the same AWS account and region with a single manipulated command.
  • Researchers at security firm BeyondTrust identified two separate vulnerabilities in the Amazon Bedrock AgentCore SDK, which the company announced on October 6, 2026.
  • Amazon released version 1.18.1 of the Bedrock AgentCore SDK to address both vulnerabilities identified by BeyondTrust.
  • The company has, according to corporate statements, committed $225 billion to its Trainium AI chip.

Amazon Web Services (AWS) has closed multiple critical security vulnerabilities in its AI service Bedrock AgentCore that could have enabled attackers to access all AgentCore agents within the same AWS account and region with a single manipulated command. Security firm Zenity Labs disclosed the vulnerabilities under the designation "AgentCorruption" on October 9, 2026.

The security vulnerabilities affected AWS Bedrock—a platform through which companies gain access to AI models from various providers and can develop their own AI agents. A successful attack could have exposed internal agents, private user conversations, source code repositories, and confidential credentials.

Two vulnerabilities in SDK uncovered

Researchers at security firm BeyondTrust identified two separate vulnerabilities in the Amazon Bedrock AgentCore SDK, as the company announced on October 6, 2026. The first vulnerability allowed attackers to exploit an incomplete blocklist to read temporary access credentials. They used specially crafted package names to bypass security controls and execute commands within the sandbox environment.

The second vulnerability was assigned the identifier CVE-2026-16796 and occurred after AWS closed the first vulnerability with version 1.6.1. Attackers exploited pip package manager extras syntax to circumvent the updated validation.

Patches available

Amazon released version 1.18.1 of the Bedrock AgentCore SDK to address both vulnerabilities identified by BeyondTrust. Version 1.6.1 had previously been released as an interim fix for the first vulnerability before the second was discovered.

Risk for AWS infrastructure investments

The vulnerabilities concentrate risk in a central control layer and strike AWS at a point where customers are particularly dependent on the company's services. The timing of the disclosure coincides with substantial infrastructure investments by Amazon in the AI space: the company has, according to corporate statements, committed $225 billion to its Trainium AI chip. The chip business is intended to generate annual revenue of over $25 billion and contribute to the high-margin AWS division.

AgentCorruption illustrates potential risks from these substantial infrastructure investments. Security vulnerabilities that could disrupt workloads or delay deal closures have a stronger impact when investments are high.

Timeline

On September 29, 2026, vulnerabilities in AgentCore were first reported that could expose AWS credentials. BeyondTrust published a detailed analysis of the two SDK vulnerabilities on October 6, 2026. Zenity Labs disclosed AgentCorruption on October 9, 2026, and patch availability was confirmed on October 10, 2026.

Earlier vulnerabilities in Bedrock

AWS Bedrock has been affected by security vulnerabilities in the past. In March 2026, a vulnerability was disclosed that enabled data exfiltration via DNS leaks. AWS rated this vulnerability with a severity score of 7.5 out of 10 points. In December 2025, the company decided to update documentation rather than release an additional patch.

Unit 42 of Palo Alto Networks uncovered critical vulnerabilities in the Amazon Bedrock AgentCore sandbox in April 2026 and demonstrated DNS tunneling and credential disclosure.

Sources

Share Article

X LinkedIn
Comments (0)

Sign in to comment.

You might also be interested in

Subscribe to newsletter

Get the most important market updates and analyses delivered to your inbox every week.