Critical Vulnerabilities in PostgreSQL Affect Multiple Versions

Critical Vulnerabilities in PostgreSQL Affect Multiple Versions

First seen 3 Sep 2026, 17:39 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

On September 3, 2026, multiple security updates were released for PostgreSQL versions 14, 15, 16, and 18, addressing a total of 24 vulnerabilities. Key vulnerabilities include CVE-2026-6464, which allows early failure processing of data lines as commands, and CVE-2026-14664, which involves a heap buffer overflow that can execute arbitrary code. Other notable vulnerabilities include issues with privilege checks and potential arbitrary file access. These vulnerabilities affect various SUSE Linux distributions, including openSUSE and SUSE Linux Enterprise Server. The updates are crucial for maintaining system security and preventing potential exploitation. Administrators are urged to apply the patches immediately to mitigate risks. The vulnerabilities were published on August 13, 2026, with proof-of-concept code for CVE-2026-14662 released on September 1, 2026.

Key Points: • Multiple PostgreSQL versions (14, 15, 16, 18) have critical vulnerabilities patched. • CVE-2026-6464 and CVE-2026-14664 are among the most severe vulnerabilities addressed. • Administrators must apply patches immediately to secure their systems against potential exploitation.

Timeline

2026-08-13
CVE-2026-6464 published
CVE-2026-6464 disclosed, allowing early failure processing of data lines as commands.
Linuxsecurity
2026-08-13
CVE-2026-14664 published
CVE-2026-14664 disclosed, which involves a heap buffer overflow that can execute arbitrary code.
Linuxsecurity
2026-08-13
CVE-2026-14666 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-6469 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14663 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-6470 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-14668 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-6471 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
Proof-of-concept for CVE-2026-14662 released
Public proof-of-concept code for CVE-2026-14662 was released, increasing exploitation risk.
Linuxsecurity
2026-09-03
Security updates released for PostgreSQL
SUSE released critical security updates for PostgreSQL versions 14, 15, 16, and 18, addressing multiple vulnerabilities.
Linuxsecurity