Linuxsecurity Flaws in PgBouncer Allow Remote Code Execution and Denial of Service
Article Content
- •Critical vulnerabilities in PgBouncer could lead to arbitrary code execution.
- •Affected versions include Fedora 43 to 45, with patches available in version 1.26.0.
- •Users should upgrade immediately to mitigate risks from CVE-2026-6665 and CVE-2026-6666.
Multiple vulnerabilities have been identified in PgBouncer, a lightweight connection pooler for PostgreSQL, affecting Fedora versions 43 to 45. The flaws, tracked as CVE-2026-6664, CVE-2026-6665, and CVE-2026-6666, could allow arbitrary code execution or denial of service via malicious SCRAM authentication packets. The vulnerabilities were disclosed on May 9, 2026, and have a CVSS score of 8.1 for CVE-2026-6665, marking it as a high severity issue. Users are advised to upgrade to PgBouncer version 1.26.0, which contains patches for these vulnerabilities. The updates were made available on September 26, 2026, and users are encouraged to apply them using the 'dnf' update program. Failure to address these vulnerabilities could expose systems to significant risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Fedora and CVE-2026-6664 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of PgBouncer are affected?
What should I do to protect my systems?
Are these vulnerabilities being actively exploited?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…