Critical PostgreSQL Vulnerability Allows Remote Code Execution
ID: 5b0b2a15-1913-511c-8908-abafe0ac05a2
STIX ID: report--5b0b2a15-1913-511c-8908-abafe0ac05a2
Feed Name: ThreatCluster
A heap-based buffer overflow (CVE-2026-14669) in PostgreSQL's to_char() function allows authenticated attackers to achieve arbitrary code execution by providing an oversized POSIX timezone abbreviation; the issue affects versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24, was disclosed on August 13, 2026 with a proof-of-concept following on August 18, and PostgreSQL has released fixes for supported branches—organisations are urged to patch immediately and monitor for potential intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
