AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions

A critical vulnerability in the AWS Systems Manager Agent could let authenticated attackers bypass remote-host port-forwarding restrictions and access sensitive link-local services, including the Amazon EC2 Instance Metadata Service. The flaw, tracked as CVE-2026-89049, affects Amazon SSM Agent versions earlier than 3.3.4851.0 and has been fixed in version 3.3.4851.0. AWS Systems Manager Agent runs on […]

This article has been indexed from Cyber Security News

Read the original article: