Yutan[verified]@yutaaaalllDisclosure
A zero‑day command‑injection vulnerability (CVE‑2026‑5059) with a CVSS score of 9.8 has been disclosed by ZDI, targeting unofficial AWS MCP servers, highlighting significant risks for privately hosted repositories.
TheZDIBugs@TheZDIBugsDisclosure
The advisory discloses a critical zero‑day AWS CLI command injection (CVE‑2026‑5059) with a CVSS score of 9.8, but provides no PoC, exploit code, active exploitation evidence, or patch information.
Autumn Good@autumn_good_35False Positive
The text notes a vendor rejection of two 0Day command-injection CVEs, with no PoC, exploit, or patch details provided, implying a false-positive or debunked report.
CVEFind.com@CveFindComDisclosure
The post announces a critical AWS CLI command injection flaw (CVE‑2026‑5059) that permits unauthenticated remote code execution.
CVE@CVEnewDisclosure
A new vulnerability (CVE-2026-5059) in AWS CLI allows remote attackers to execute arbitrary code via command injection.
PulsePatch.io@pulsepatchioDisclosure
A critical command injection flaw in aws‑mcp could allow remote code execution; stakeholders should assess exposure and plan remediation.
0day Signal@0dayPublishingPatch
The post announces CVE‑2026‑5059 as an unauthenticated remote code execution flaw in AWS MCP server command injection with a CVSS 9.8 score, urging users to apply patches immediately.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text references CVE-2026-5059, noting it as unauthenticated command injection that results in RCE on the aws-mcp-server, with a link to a detailed vulnerability page.