
Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials
A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal temporary IAM credentials assigned to Amazon EC2 instances. Tracked as CVE-2026-89049, the issue affects AWS Systems Manager Agent versions earlier than 3.3.4851.0. GitHub Security Advisory GHSA-w9jw-h72g-6hxc3 classifies the flaw as […]
The post Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials appeared first on Cyber Security News.