CVE-2026-5747Disclosure(amazon / firecracker)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch amazon firecracker systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-369CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firecracker

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
firecracker

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-04-07: 1Mentions · 2026-04-08: 3Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-06-11: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 104-0704-0804-0904-1006-1109-22
Signal classification3 categories
Disclosure
337.5%
General
337.5%
Patch
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-071
Patch1
2026-04-083
Disclosure1General1Patch1
2026-04-091
Disclosure1
2026-04-101
Disclosure1
2026-06-111
General1
2026-09-221
General1
Full discourse8 posts
  • NiNi@terrynini38514
    General

    It's always less impressive if you disclose vulnerabilities after everything has settled down. We also found CVE-2026-5747 with Codex before Mythos reported it, because we were trying to make it possible for Pwn2Own, but things change quickly in the AI era. We found a bypass on the same day CVE-2026-5747 was disclosed. I thought most people don't credit LLM agents like Anthropic always does, so I wrote the acknowledgement as "NiNi (@terrynini38514) from DEVCORE Research Team and Codex Pro (@OpenAI)", but it got censored now😂😂😂 It was quite entertaining. Keep looking for the next vuln in the world.

    Post summary

    The user reports discovering CVE-2026-5747 and finding a bypass, but provides no technical details, PoC, exploit code, or patch information.

    11111334315.4K
    3.1K followersView on X
  • Michel Maalouli@michelmaalouli_
    General

    Claude voice mode has no guardrails? It literally tried to break out of its code execution tool sandbox and access the Firecracker VMM. Wouldn’t be surprised if it does. Latest CVE for Firecracker was credited to Anthropic. https://www.cve.org/CVERecord?id=CVE-2026-5747 https://t.co/7EDwZzqrsF

    Post summary

    The text mentions CVE-2026-5747 and an anecdotal Claude sandbox-breakout attempt, but lacks explicit indicators of PoC, exploit tooling, active exploitation, patching, or detailed vulnerability mechanics.

    10020117
    36 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5747: HIGH] Critical out-of-bounds write issue in Amazon Firecracker! Upgrade to version 1.14.4 or 1.15.1 to patch vulnerability allowing local user to crash VMM or execute malicious code.#cve,CVE-2026-5747,#cybersecurity https://cvefind.com/CVE-2026-5747

    Post summary

    The tweet announces that Amazon Firecracker has a critical out-of-bounds write vulnerability (CVE‑2026‑5747) and provides the exact patch versions to mitigate the issue.

    00010514
    619 followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [HIGH] - AWS has disclosed a high-severity vulnerability (CVE-2026-5747, CVSS 8.7) in Firecracker, the open-source microVM virtualization technology that underpins critical AWS services including Lambda and Fargate. The vulnerability... https://www.enigma-global.com/og/report/cve-2026-5747-high-severity-out-of-bounds-write-in-aws-firecracker-virtio-pci-mnqe0y7k-z8ws

    Post summary

    AWS discloses a high‑severity out‑of‑bounds write in Firecracker (CVE‑2026‑5747, CVSS 8.7), but no PoC, exploit, or patch information is provided.

    0000042
    2 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport http://dlvr.it/TRyKWR #patchmanagement

    Post summary

    The CVE-2026-5747 entry highlights an out-of-bounds write in Firecracker's virtio-pci transport, providing the vulnerability details and a link, but does not mention exploitation, patches, or false positives.

    0000044
    2.0K followersView on X
  • CyberBriefDaily@CyberBriefDaily
    Patch

    🛡️ Cyber Byte #15 Amazon Firecracker Out-of-Bounds Write CVE-2026-5747: Local guest user with root privileges can crash Firecracker VMM or potentially run code on host (virtio PCI transport). Fix: Update to Firecracker v1.14.4 or v1.15.1 immediately. 🔗 https://aws.amazon.com/security/security-bulletins/2026-015-aws/ #Firecracker #Virtualization #OutOfBounds #AWS #CyberSecurity #CyberBriefDaily

    Post summary

    The bulletin announces CVE-2026-5747, detailing an out‑of‑bounds write in Amazon Firecracker that allows a privileged guest to crash or execute code on the host, and urges users to upgrade immediately to patched versions v1.14.4 or v1.15.1.

    0000098
    4 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5747 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5747 #CVE-2026-5747 #CVE #High #CyberSecurity #InfoSec https://t.co/8ebTyUVL0N

    Post summary

    The tweet merely announces a new CVE-2026-5747 with a high severity score, without providing details on exploitation, mitigation, or technical specifics.

    0000039
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5747 An out-of-bounds write issue in the virtio PCI transport in Amazon Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user wit… https://www.cve.org/CVERecord?id=CVE-2026-5747

    Post summary

    The text announces a CVE for an out‑of‑bounds write in Amazon Firecracker’s virtio PCI transport that could be exploited by a local guest.

    00000254
    57.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonfirecracker---
Appamazonfirecracker1.15.0--
Appamazonfirecracker1.15.0--

Explore more