CVE-2026-15746: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory to...

Added to the CISA Known Exploited Vulnerabilities catalog on 15 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the elasticsearch_memory tool for agent memory storage. We identified CVE-2026-15746, a server-side request forgery (SSRF) issu...

Required action: Review and patch if applicable to your AI infrastructure.