ThreatsCloud & SaaSHighCritical AWS HealthLake MCP Server Flaw Exposes Cloud IAM Credentials and Healthcare Telemetry to SSRF CVE-2026-15643AWS discloses high-severity SSRF flaw CVE-2026-15643 in the HealthLake MCP server, enabling attackers to leak temporary SigV4 IAM credentials and healthcare FHIR records.Priya Raman·26 Sep 2026, 00:00 IST·17 min read