Microsoft disclosed two high-severity database-related vulnerabilities affecting PgBouncer and PostgreSQL, including CVE-2026-6665, a stack-based buffer overflow in PgBouncer's SCRAM authentication handling, and CVE-2026-6637, which affects PostgreSQL's refint component and can allow both a stack buffer overflow and SQL injection. The PgBouncer issue is classified as CWE-121 and carries a CVSS 8.1 score, indicating high potential impact to confidentiality, integrity, and availability.
According to Microsoft's advisory, CVE-2026-6665 is remotely reachable over the network, requires no privileges and no user interaction, though exploitation is assessed as having high attack complexity. The related PostgreSQL refint flaw broadens the risk profile by combining memory corruption with SQL injection exposure, raising concern for organizations running PostgreSQL environments directly or behind PgBouncer connection pooling layers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-6637 covering a PostgreSQL refint issue that allows stack buffer overflow and SQL injection. No additional synopsis details were provided in the reference.
Microsoft published a security notice for CVE-2026-6665 describing a stack-based buffer overflow in PgBouncer’s SCRAM handling. The advisory rates the flaw CVSS 8.1 and notes it is remotely reachable with no privileges or user interaction required, though exploitation has high attack complexity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bugzilla.suse.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcesecurity-tracker.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.