CVE-2026-65321Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-08-02); latest day: 2
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-07-31: 1Mentions · 2026-08-02: 5Mentions · 2026-08-03: 2PoC Mentioned / Linked · 2026-08-02: 1Patch / Workaround · 2026-08-02: 2Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-02: 4Technical Details · 2026-08-03: 207-3108-0208-03
Signal classification4 categories
Disclosure
337.5%
General
225.0%
Patch
225.0%
PoC
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-07-311
General1
2026-08-025
Disclosure2General1Patch1PoC1
2026-08-032
Disclosure1Patch1
Full discourse8 posts
  • laughingman7743@laughingman7743
    Disclosure

    Blogged✍️ A SQL injection in PyAthena's parameter formatter (CVE-2026-65321) - /var/log/laughingman7743.log https://laughingman7743.hatenablog.com/entry/2026/08/03/225426

    Post summary

    A blog post announces a SQL injection flaw in PyAthena’s parameter formatter (CVE‑2026‑65321).

    0001063
    108 followersView on X
  • MalwareObserver@MalwareObserver
    PoC

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-65321](https://github.com/laughingman7743/PyAthena) PyAthena prior to 3.35.4 contains a... https://github.com/laughingman7743/PyAthena #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces CVE‑2026‑65321 impacting PyAthena before version 3.35.4 and supplies a GitHub link that presumably hosts proof‑of‑concept code, but no exploit tools, patches, or evidence of active exploitation are mentioned.

    0001051
    18 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐🚨 PyAthena SQL Injection — CVSS 9.8 CVE-2026-65321: Unauthenticated SQL injection via improper quote-escaping in DefaultParameterFormatter. Update to 3.35.4 NOW. → http://threataft.com/articles/pyathena-cve-2026-65321 #cybersecurity #infosec #PyAthena #AWS #DataSecurity #ThreatIntel

    Post summary

    The post announces CVE-2026-65321—a high‑severity unauthenticated SQL injection in PyAthena—provides a CVSS score, notes a patch release to 3.35.4, and links to a detailed article.

    0000048
    36 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    PyAthena versions before 3.35.4 contain a CVSS 9.8 SQL injection vulnerability. Update immediately if this library is in use. https://nvd.nist.gov/vuln/detail/CVE-2026-65321 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/bDDF3ZgNuL

    Post summary

    The tweet highlights a high‑severity SQL injection vulnerability (CVE-2026-65321) in PyAthena and urges users to update the library immediately.

    0000073
    90 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-65321 PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in… https://www.cve.org/CVERecord?id=CVE-2026-65321

    Post summary

    The message discloses a SQL injection flaw in PyAthena, detailing its nature without evidence of exploitation or mitigation, firmly placing it in the disclosure category.

    00000795
    57.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - PyAthena SQLi via broken quote escaping in DefaultParameterFormatter (CVE-2026-65321) PyAthena DefaultParameterFormatter.format() uses _escape_hive to backslash-escape single quotes, but Athena/Trino string literals don’t treat backslashes as escapes. Crafted parameters in DELETE or CTAS can break out of quotes to inject UNION SELECT/exfiltration, destructive SQL, or attacker-controlled CTAS output. SELECT-only queries aren’t impacted. 👉Affected: PyAthena < 3.35.4 | Upgrade to 3.35.4

    Post summary

    The post announces a critical SQL injection in PyAthena’s DefaultParameterFormatter, explains how backslash‑escaped quotes are mishandled, and advises users to upgrade to version 3.35.4 to mitigate the issue.

    00000106
    279 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-65321 SQL Injection in PyAthena Prior to 3.35.4 via Improper Quote-Escaping https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-65321

    Post summary

    The post notes CVE-2026-65321 as a SQL injection in PyAthena versions before 3.35.4, yet it offers no PoC, exploit details, patch information, or active exploitation evidence.

    00000140
    4.1K followersView on X
  • laughingman7743@laughingman7743
    General

    https://github.com/pyathena-dev/PyAthena/security/advisories/GHSA-xwj5-g6cv-4r5c CVE-2026-65321🙏

    Post summary

    The snippet references a GitHub security advisory and a CVE but provides no further details, making it a general mention without actionable information.

    0000055
    108 followersView on X

Explore more