Microsoft published security advisories for two database-related vulnerabilities affecting PostgreSQL and PgBouncer, both tied to integer handling errors that can destabilize services. CVE-2026-6473 describes a PostgreSQL server flaw in which allocations can be undersized because of integer wraparound, while CVE-2026-6664 affects PgBouncer network packet parsing and is classified as an integer overflow issue under CWE-190.
The PgBouncer flaw carries a CVSS v3.1 score of 7.5 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a remotely exploitable issue that requires no privileges or user interaction and can cause a high availability impact, including denial of service. Microsoft released the PgBouncer notice on May 10 and later updated it, while the PostgreSQL advisory was published on May 16, signaling active vendor attention to memory-allocation and packet-parsing weaknesses in widely used database infrastructure components.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-6473, described as a PostgreSQL server vulnerability involving undersized allocations via integer wraparound. No additional synopsis details were provided in the reference.
Microsoft last updated its CVE-2026-6664 security notice after the initial release. The reference indicates the advisory was updated on May 13, 2026.
Microsoft released a security notice for CVE-2026-6664, an integer overflow vulnerability in PgBouncer network packet parsing. The advisory rated the flaw CVSS 7.5 and noted it is remotely exploitable with high availability impact.
A PostgreSQL source code commit titled "libpq: Prevent some overflows of int/size_t" was published in the postgres repository. The change appears to address integer overflow conditions in libpq before Microsoft later published its advisory for CVE-2026-6473.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.