PostgreSQL released security updates for supported branches to fix multiple high-severity vulnerabilities affecting versions before 14.23, 15.18, 16.14, 17.10, and 18.4. The most serious issues include CVE-2026-6473, an integer wraparound bug that can cause undersized allocations and out-of-bounds writes, and CVE-2026-6637, a flaw in the refint module that can lead to a stack buffer overflow. In both cases, an unprivileged database user may be able to achieve arbitrary code execution as the operating system account running PostgreSQL.
The refint issue also exposes a separate SQL injection path when applications use a user-controlled column as a refint cascade primary key and allow user-controlled updates, potentially enabling arbitrary SQL execution as the database user performing the update. Debian issued security advisories for postgresql-15 and postgresql-17, and the Canadian Centre for Cyber Security urged administrators to review PostgreSQL’s advisory and deploy the patched releases 14.23, 15.18, 16.14, 17.10, and 18.4.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
PostgreSQL announced an end-of-life date for version 14 alongside its May 2026 security release information. The lifecycle notice was highlighted by Belgium's CCB in an advisory urging users to patch immediately and plan upgrades from version 14.
The libpng-apng advisory identified the primary upstream fix for CVE-2026-40930 as commit faf0692468 on the libpng18 branch and noted downstream fixed revisions including libpng-1.6.57-apng.patch v2 and libpng-1.6.58-apng.patch. It also highlighted a separate related push-mode fdAT defect fixed by commit 9ec49c2d56 that downstream users should apply for full remediation.
A security advisory disclosed CVE-2026-40930, a chunk-smuggling vulnerability in the push-mode APNG parser used by the third-party libpng-apng patch and the libpng 1.8.0 development branch. The advisory said upstream libpng 1.6.x is not affected, but downstream consumers such as Firefox, Thunderbird, and some Linux distributions may be impacted if they use vulnerable APNG patch revisions.
The Canadian Centre for Cyber Security published advisory AV26-470 summarizing PostgreSQL's May 14 security release and recommending that administrators review the vendor advisory and apply updates. The notice referenced the patched versions 14.23, 15.18, 16.14, 17.10, and 18.4.
Debian released DSA 6269-1 for postgresql-15 and DSA 6270-1 for postgresql-17, providing security updates for those packages. Both advisories were published on May 14, 2026.
PostgreSQL published a security advisory for CVE-2026-6575 describing a flaw in pg_restore_attribute_stats where accepted values can cause query planning to read past the end of a statistics array. The issue was disclosed as part of PostgreSQL's May 14, 2026 security release.
PostgreSQL published a security advisory for CVE-2026-6476 describing an SQL injection vulnerability in pg_createsubscriber via subscription name handling. The issue was disclosed as part of PostgreSQL's May 14, 2026 security release.
PostgreSQL published a security advisory for CVE-2026-6474, describing an information disclosure flaw in the timeofday() function that can expose portions of server memory. The issue was disclosed as part of PostgreSQL's May 14, 2026 security release.
PostgreSQL published a security advisory for CVE-2026-6638, describing an SQL injection vulnerability in REFRESH PUBLICATION via table name handling. The disclosure was part of PostgreSQL's May 14, 2026 security release.
A CVE entry was published for vulnerabilities in PostgreSQL's refint module, including a stack buffer overflow that may permit arbitrary code execution as the database OS user and a separate SQL injection path in certain application configurations. Affected versions were listed as releases before 18.4, 17.10, 16.14, 15.18, and 14.23.
A CVE entry was published for an integer wraparound vulnerability in multiple PostgreSQL server features that can cause undersized allocations and out-of-bounds writes. The issue can allow an unprivileged database user to achieve arbitrary code execution as the database OS user or trigger crashes in some application scenarios.
PostgreSQL published a security advisory for CVE-2026-6472 describing a flaw where CREATE TYPE does not properly check multirange schema CREATE privilege. The issue was disclosed as part of PostgreSQL's May 14, 2026 security release.
PostgreSQL published a security advisory covering supported branches and released fixes in versions 14.23, 15.18, 16.14, 17.10, and 18.4. The advisory addressed multiple flaws, including CVE-2026-6473 and CVE-2026-6637, affecting earlier releases.
Debian published security advisory DSA 6263-1 for libpng1.6, indicating a security update for the package. The advisory was released on May 10, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcecybersecuritynews.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcecvefeed.io
Open sourcelists.debian.org
Open sourcelists.debian.org
Open sourcelists.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.