CVE-2026-15746: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory to...
Added to the CISA Known Exploited Vulnerabilities catalog on 15 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.
Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issu...
Required action: Review and patch if applicable to your AI infrastructure.