Linuxsecurity Critical Vulnerabilities in PostgreSQL 18 and 16 Require Immediate Attention
Article Content
- •Multiple critical vulnerabilities in PostgreSQL 18 and 16 require immediate patching.
- •CVE-2026-2004, CVE-2026-2005, and CVE-2026-2006 are rated 8.8 on the CVSS scale.
- •Affected users include those on openSUSE and SUSE Linux Enterprise systems.
On March 12, 2026, updates for PostgreSQL versions 16 and 18 were released, addressing multiple critical vulnerabilities. Key issues include CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, and CVE-2026-2007, all published on February 12, 2026. These vulnerabilities could lead to arbitrary code execution and memory disclosure, affecting server security. Users of openSUSE and SUSE Linux Enterprise are particularly at risk and are advised to apply the patches immediately. The updates also include regression fixes for issues related to the substring() function and multibyte character handling. The vulnerabilities are significant, with CVE-2026-2004, CVE-2026-2005, and CVE-2026-2006 rated 8.8 on the CVSS scale, indicating high severity. The current status is that patches are available, and users are urged to update their systems promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track OpenSUSE and CVE-2026-2003 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…