Amazon disclosed CVE-2026-7461, an OS command injection flaw in the Amazon ECS Agent for Windows that can let a remote authenticated actor execute shell commands as SYSTEM on the underlying host. The vulnerability affects ECS agent versions 1.47.0 through 1.102.2 and stems from improper input validation during the mounting of FSx Windows File Server volumes, where a specially crafted username field in an ECS task definition can trigger command execution.
The issue is limited to ECS Windows worker instances and does not affect ECS on Fargate. Amazon said exploitation requires the ability to register ECS task definitions or to modify credentials in AWS Secrets Manager or SSM Parameter Store referenced by the FSx volume configuration. The company fixed the flaw in ECS agent version 1.103.0 and advised customers to upgrade to the latest ECS-optimized Windows AMI; as interim mitigations, AWS recommended restricting ecs:RegisterTaskDefinition permissions and limiting write access to the affected secrets.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
AWS published security bulletin AWS-2026-024 covering CVE-2026-7461, documenting the OS command injection issue in Amazon ECS Agent via FSx Windows File Server volume credentials. The bulletin formalized the vendor advisory for customers tracking AWS security notices.
Amazon fixed the vulnerability in Amazon ECS Agent version 1.103.0 and advised customers to upgrade to the latest Amazon ECS-optimized Windows AMI. AWS also recommended interim mitigations including restricting ecs:RegisterTaskDefinition permissions and limiting write access to referenced secrets in AWS Secrets Manager or SSM Parameter Store.
Amazon disclosed CVE-2026-7461, an OS command injection flaw in the Amazon ECS Agent for Windows affecting versions 1.47.0 through 1.102.2. The issue stems from improper input validation in FSx Windows File Server volume mounting and could allow a remote authenticated actor to execute commands as SYSTEM on ECS Windows worker instances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourceaws.amazon.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.