CVE-2026-18654PoC

LOWCVSS 6.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-322

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-06: 1Mentions · 2026-08-08: 1PoC Mentioned / Linked · 2026-08-06: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-08: 108-0608-08
Signal classification2 categories
PoC
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-061
PoC1
2026-08-081
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 #AWS CLI (#Amazon Web Services Command Line Interface), Improper Authentication - SSH Host Key Disabled (#CVE-2026-18654) (Medium) -DC-Aug2026-1469 https://dailycve.com/aws-cli-amazon-web-services-command-line-interface-improper-authentication-ssh-host-key-disabled-cve-2026-18654-medium-dc-aug2026-1469/

    Post summary

    The content announces CVE‑2026‑18654, highlighting an improper authentication flaw in AWS CLI caused by disabled SSH host keys; no PoC, exploit, or mitigation details are provided.

    0000051
    226 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    PoC

    CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands http://dlvr.it/TTtfTx #patchmanagement

    Post summary

    A CVE (CVE-2026-18654) indicating disabled SSH host key verification in AWS CLI EMR helper commands is disclosed with a likely PoC link, but no exploit code, active exploitation, or patch is referenced.

    0000059
    2.0K followersView on X

Explore more