logo

Critical PostgreSQL Vulnerability Allows Remote Code Execution

ID: 5b0b2a15-1913-511c-8908-abafe0ac05a2

STIX ID: report--5b0b2a15-1913-511c-8908-abafe0ac05a2

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

...
...

A heap-based buffer overflow (CVE-2026-14669) in PostgreSQL's to_char() function allows authenticated attackers to achieve arbitrary code execution by providing an oversized POSIX timezone abbreviation; the issue affects versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24, was disclosed on August 13, 2026 with a proof-of-concept following on August 18, and PostgreSQL has released fixes for supported branches—organisations are urged to patch immediately and monitor for potential intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.