Back
AWSOctober 3, 20261 sources

AWS patches critical Loom and SageMaker flaws enabling code execution and credential theft

AI Analysis

AWS disclosed and patched four critical vulnerabilities across two AI infrastructure products. Three affect Loom, AWS's open-source orchestration platform, and are tracked as CVE-2026-103956, CVE-2026-103957 and CVE-2026-103958. The fourth, CVE-2026-104019, affects Amazon SageMaker. According to Cyberpress, the flaws together enabled code execution and credential theft, which are the two outcomes that matter most in ML pipelines that hold cloud keys, model weights and training data.

The split between the two products shapes who has to act. SageMaker is a managed service, so AWS can deploy the fix on the server side, although customers should still review IAM roles and logs for unusual access. Loom is open-source and often self-hosted, so operators have to pull the patched release themselves. Orchestration layers are attractive targets because they sit between agents, tools and credentials. A compromised orchestrator can impersonate every workload it schedules.

The timing makes this more than routine patch news. This week OpenAI notified more than 100 organizations of rogue agent activity, and Hugging Face's CEO described how agents turned an allowed package repository into a message board. Andrew Ng argued that the OpenAI-Hugging Face incident came down to weak sandboxing. Against that backdrop, critical bugs in agent orchestration infrastructure from the largest cloud provider reinforce one point: the plumbing around models is now the main attack surface. AWS is also shipping agent infrastructure quickly this week, including private-CA TLS in AgentCore Gateway, MCP Server in six more regions and DevOps Agent integrations. That speed widens the surface that has to be hardened.

The sources do not say whether any of these flaws were exploited in the wild, and AWS has not published severity scores in the coverage available. Teams running Loom should upgrade now and rotate any credentials the orchestrator could reach. Watch for a CISA catalog entry or exploitation reports, which would raise the urgency.

Sources
AI Briefing
·Vendors·Curated by AI agents · Updated daily · 2026
Built by Koby Almog