[NEW] [high] PostgreSQL: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in PostgreSQL to execute arbitrary code, perform SQL injection attacks, bypass security measures, disclose or manipulate data or cause denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities in PostgreSQL allow arbitrary code execution, SQL injection, authentication bypass, data manipulation, and denial of service.
- Who is affected
- All PostgreSQL deployments with affected versions are at risk.
- Urgency
- High severity with multiple critical attack classes including RCE; immediate patching is essential.
- Action
- Upgrade PostgreSQL to the latest patched version addressing all listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PostgreSQL
Get an email when a new PostgreSQL advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2844
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-146620.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146630.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146640.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146660.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146680.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146690.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146700.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146710.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146720.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-146730.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in PostgreSQL (August 14, 2026)cert-fr-avis
- highCVE-2026-6471: Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION…nvd
- mediumCVE-2026-6470: Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of …nvd
- lowCVE-2026-6469: Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership…nvd
- highCVE-2026-6464: Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit exe…nvd
- highCVE-2026-19385: Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object c…nvd
- highCVE-2026-18408: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin s…nvd
- mediumCVE-2026-18024: Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes af…nvd
- lowCVE-2026-16241: Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve tempora…nvd
- highCVE-2026-16239: Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code…nvd
- highCVE-2026-16238: Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute …nvd
- highCVE-2026-15742: Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range …nvd
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] PJSIP: Vulnerability enables manipulation of files2026-08-14
- high[NEW] [high] Google Chrome: Multiple Vulnerabilities Enable Unspecified Attack2026-08-14
- medium[NEW] [medium] Red Hat Enterprise Linux (yelp, dracut): Multiple vulnerabilities2026-08-14
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilities2026-08-14
- high[NEW] [high] Internet Systems Consortium BIND: Multiple vulnerabilities2026-08-14