Warning: Vulnerability in PostgreSQL Allows Remote Code Execution, Proof-Of
CVE-2026-14669 is a Heap-based Buffer Overflow vulnerability in PostgreSQL, one of the most widely used database technologies worldwide. The vulnerability is located in PostgreSQL’s built-in to_char() date/time formatting functionality, which is part of PostgreSQL’s standard core functionality.
Successful exploitation of CVE-2026-14669 can result in arbitrary code execution with the privileges of the PostgreSQL operating-system account. This could allow an attacker to compromise the database server and potentially access, modify or destroy data and disrupt database availability.
A public proof-of-concept demonstrating remote code execution has been published, increasing the urgency for organisations running affected versions to patch immediately.
The vulnerability exists in PostgreSQL's date/time formatting implementation. The affected to_char() code allocates a working buffer based on the length of the format string, but the TZ and TZtz processing paths can copy a user-controlled POSIX timezone abbreviation into that buffer without adequately checking its length.
An authenticated attacker can supply an oversized timezone abbreviation and trigger a heap buffer overflow. According to the publicly available technical analysis, exploitation can corrupt adjacent heap data and, under suitable conditions, ultimately execute attacker-controlled code within the PostgreSQL backend process.
PostgreSQL released fixes for all supported affected branches on 13 August 2026. The vulnerability is fixed in PostgreSQL 18.5, 17.11, 16.15, 15.19 and 14.24.
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case of an intrusion, you can report an incident via . While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
