logo

Warning: Vulnerability in PostgreSQL Allows Remote Code Execution, Proof-Of-Concept Available, Patch Immediately!

ID: b6c867cb-b45e-53a7-871e-f966a6326098

STIX ID: report--b6c867cb-b45e-53a7-871e-f966a6326098

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

...
...

CVE-2026-14669 is a heap-based buffer overflow in PostgreSQL's to_char() date/time formatting (TZ/TZtz) that allows an authenticated attacker to supply an oversized timezone abbreviation to trigger a heap overflow and potentially achieve arbitrary code execution. PostgreSQL released fixes on 13 August 2026 for supported branches (fixed in 18.5, 17.11, 16.15, 15.19, 14.24); a public proof-of-concept exists and organizations are advised to patch immediately and increase monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.