Linuxsecurity Critical PostgreSQL Vulnerabilities in Oracle Linux 8 and 9
Article Content
- •CVE-2026-6478 affects PostgreSQL 15, requiring immediate patching.
- •Oracle Linux 8 and 9 users must update their PostgreSQL installations to mitigate risks.
- •Multiple modules including pgaudit and pg_repack have received critical updates.
Oracle Linux has released important security advisories for PostgreSQL vulnerabilities affecting versions 15 and 16. CVE-2026-6478, a critical vulnerability, has been identified in PostgreSQL 15, prompting immediate updates. The vulnerabilities impact Oracle Linux 8 and 9, with specific advisories ELSA-2026-28037 and ELSA-2026-28143 detailing the necessary patches. PostgreSQL 16 is also affected, with updates available for pgaudit, pg_repack, and postgis modules. Administrators are urged to apply the patches promptly to mitigate risks. The vulnerabilities could lead to unauthorized access and data breaches if left unaddressed. The advisories emphasize the urgency of updating systems to the latest versions to protect against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-6473 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Exploitation Confirmed Citrix has confirmed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in its NetScaler ADC and Gateway products, both scoring 9.5 on the CVSS scale. These vulnerabilities are actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary commands and potentially cause…