PostgreSQL has released security updates for all supported branches after fixing 28 vulnerabilities, including several high-severity flaws that could lead to remote code execution or full compromise of database instances. Patched versions are 14.24, 15.19, 16.15, 17.11, and 18.6. Among the most serious issues are CVE-2026-14662, an out-of-bounds write involving the tsvector and tsquery data types, and CVE-2026-18408, which can enable code execution during the database restore process.
Additional high-impact bugs disclosed in the same release include CVE-2026-14669, a heap buffer overflow in to_char(timestamptz) triggered by long POSIX timezone abbreviations and rated CVSS 8.8, and CVE-2026-14679, an argument-matching flaw that permits controlled out-of-bounds writes on the stack and carries a CVSS 8.2 score. Successful exploitation of these vulnerabilities could allow attackers to execute code as the operating-system user running PostgreSQL. PostgreSQL said it had no reports of active exploitation at publication time and also warned that support for PostgreSQL 14 ends on November 12, 2026, after which it will no longer receive security fixes.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
PostgreSQL CNA records disclosed CVE-2026-14680 and CVE-2026-16238, two high-severity flaws rated 8.8 that can lead to code execution with the database server's operating-system privileges. The records directly credit Amy Burnett of OpenAI Codex Security for reporting both issues, which were fixed in PostgreSQL's August 2026 security release.
PostgreSQL CNA records disclosed CVE-2026-14676, CVE-2026-15741, CVE-2026-15742, and CVE-2026-16239, all rated 8.8 upstream, covering a pg_stat_statements heap overflow, SQL injection during expression deparsing, an effectively arbitrary-address write in fuzzystrmatch, and a cursor-state type confusion. The records credit Ben Morris with Claude and Anthropic Research on three CVEs and David Korczynski with Claude and Ada Logics on CVE-2026-14676, with shared credit on that issue.
PostgreSQL released patched versions 14.24, 15.19, 16.15, 17.11, and 18.6 in its August 2026 security release. The update fixes 28 vulnerabilities, including high-severity issues such as CVE-2026-14662, CVE-2026-18408, CVE-2026-14669, and CVE-2026-14679 that could enable malicious code execution or memory corruption.
PostgreSQL disclosed CVE-2026-14679, an argument-matching flaw that permits controlled zero and one bytes to be written outside a stack buffer. The CNA record assigned the issue a CVSS score of 8.2 and directly credited Zheng Yu of DepthFirst AI alongside another independent reporter.
PostgreSQL disclosed CVE-2026-14669, a heap buffer overflow in to_char(timestamptz) triggered by long POSIX timezone abbreviations. The CNA record assigned it a CVSS score of 8.8 and credited multiple independent reporters, including Amy Burnett of OpenAI Codex Security and a separate self-reported path from V12.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourceheise.de
Open sourcebugflation.com
Open sourcebugflation.com
Open sourcepostgresql.org
Open sourcebugflation.com
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.