Red Hat, Oracle Linux, and AlmaLinux released PostgreSQL security updates addressing broad sets of vulnerabilities, including CVE-2026-18408, a restore-time arbitrary-code-execution flaw in malicious pg_dump output, and CVE-2026-14662, where crafted tsvector or tsquery inputs can trigger an out-of-bounds write and potentially execute code as the PostgreSQL operating-system account. CVE-2026-18408 can cause code execution under the client account restoring a dump through psql meta-command expansion; pg_dumpall and some pg_restore workflows are also affected. PostgreSQL fixed these flaws in 18.5, 17.11, 16.15, 15.19, and 14.24.
The updates also address CVE-2026-6476, which permits users with pg_create_subscription rights to arrange superuser SQL execution when pg_createsubscriber runs, and CVE-2026-6638, a logical-replication SQL injection triggered by a crafted replicated table name during ALTER SUBSCRIPTION ... REFRESH PUBLICATION. Red Hat’s Important RHEL 10 advisory RHSA-2026:67280 updates postgresql18 to 18.6 and covers 19 CVEs; Oracle Linux 9 and AlmaLinux 10 advisories similarly cover PostgreSQL 16/18 packages and report exploits as available. Organizations should promptly apply vendor updates, prioritize internet-exposed databases, restrict untrusted dump restoration and subscription-management privileges, and review affected extensions and client tooling.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Oracle Linux published ELSA-2026-67848 for PostgreSQL 18, extensions, and related packages on Oracle Linux 9. The advisory addresses 20 CVEs and states that exploits are available.
Oracle Linux published ELSA-2026-67491 for PostgreSQL 16 and related packages on Oracle Linux 9. The update addresses 17 CVEs, including CVE-2026-18408, CVE-2026-19385, and CVE-2026-73515, and the advisory states that exploits are available.
AlmaLinux published ALSA-2026:67280 for PostgreSQL 18 packages on AlmaLinux 10. The advisory addresses 19 CVEs spanning memory-safety flaws, integer overflows, SQL injection, code injection, and related weaknesses, and reports that exploits are available.
Red Hat released Important advisory RHSA-2026:67280 for PostgreSQL 18 on RHEL 10, updating packages to postgresql18-18.6-1.el10_2. The update fixes 19 vulnerabilities, including arbitrary-code-execution issues in pg_dump and tsvector/tsquery, as well as SQL injection in pg_createsubscriber.
PostgreSQL disclosed CVE-2026-6638, a low-severity SQL-injection flaw in logical replication that a malicious publisher can trigger through a crafted replicated table name when a subscriber refreshes a publication. Fixes were released in PostgreSQL 18.4, 17.10, and 16.14.
Red Hat addressed CVE-2026-14662, an integer-wraparound flaw in tsvector and tsquery that can lead to out-of-bounds writes and possible code execution, and CVE-2026-18408, a restore-time code-execution flaw involving untrusted pg_dump output, through RHSA-2026:67491 for RHEL 9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugflation.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.