logo

Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities

ID: ad8f0dd2-86d7-57d8-8b8f-28180674558a

STIX ID: report--ad8f0dd2-86d7-57d8-8b8f-28180674558a

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Waqas

...
...

Wiz researchers disclosed two critical pgcrypto vulnerabilities in PostgreSQL (CVE-2026-2005 and CVE-2026-2006) that enable heap buffer overflows and memory corruption during PGP public-key and symmetric decryption, potentially allowing attackers with minimal privileges to escalate to database-owner execution; a separate MariaDB JSON schema overflow (CVE-2026-32710) was also reported. PostgreSQL and MariaDB published patches across supported branches; administrators are advised to update immediately, restrict extension creation, and audit for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.