Critical PostgreSQL Vulnerabilities Disclosed Affecting Multiple Versions

Critical PostgreSQL Vulnerabilities Disclosed Affecting Multiple Versions

First seen 20 Aug 2026, 15:42 UTC UbuntuLinuxsecurity 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in PostgreSQL, including issues with COPY FROM STDIN, extended statistics ownership, and USAGE privilege checks. These vulnerabilities, identified as CVE-2026-6464, CVE-2026-6469, and CVE-2026-6470, could allow authenticated users to execute arbitrary SQL commands or obtain sensitive information. Additionally, CVE-2026-6471 allows arbitrary code execution via logical decoding. The vulnerabilities affect PostgreSQL versions 14, 16, and 18. Affected users are advised to update their systems immediately to mitigate risks. The vulnerabilities were published on August 13, 2026, with a proof of concept for CVE-2026-6469 released shortly before the advisory. The current status is that patches are available and users are urged to apply them.

Key Points: • Multiple critical vulnerabilities in PostgreSQL could allow SQL injection and arbitrary code execution. • Affected versions include PostgreSQL 14, 16, and 18, impacting authenticated users. • Patches are available; immediate updates are recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2025-08-14
CVE-2025-8714 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
Multiple CVEs published for PostgreSQL vulnerabilities
CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, and others were disclosed, affecting various PostgreSQL versions.
Ubuntu
2026-08-13
CVE-2026-14663 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14679 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-15742 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-6470 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14662 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-19385 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14664 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14680 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →

Tracked Entities in This Story