CyberSecurityBoardThreat Intel · CVEs · Products

Tag: AgentCore

Cyber Products

Amazon Bedrock AgentCore Vulnerability

AgentCore's InvokeHarness API had a vulnerability allowing tool-use block injection, fixed by AWS. The underlying open-source Strands code remains vulnerable.

AgentCore Amazon Bedrock AgentCore AWS CVE-2026-18830
August 6, 2026
Cyber Companies

Amazon Web Services (AWS) Agent Security

AWS patched a critical vulnerability in Amazon Bedrock AgentCore's InvokeHarness API, but the open-source Strands code remains vulnerable. The company documented the…

AgentCore Amazon Web Services AWS security
June 29, 2026