Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code on Database Servers

A newly disclosed PostgreSQL vulnerability , tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access to execute arbitrary code on database servers. The flaw in PostgreSQL logical decoding existed for roughly 12 years and has now been fixed in supported releases. PostgreSQL is widely used to store business data, application records, customer details, financial information, and cloud workloads. The vulnerability is especially concerning because it affects an account type commonly used for backups, replication, disaster recovery, and change data capture operations. The issue affects non-superuser PostgreSQL accounts that have the REPLICATION attribute. These accounts are typically used to support database replication, allowing standby servers and backup systems to receive database changes from the primary server.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code , escalate to database superuser privileges, and establish persistent access on vulnerable servers. Tracked as CVE-2026-6471, the flaw was discovered by Cyera Research and affects PostgreSQL versions dating back to 9. 4, released in 2014. PostgreSQL addressed the issue in its August 22, 2026 security release, ending a vulnerability window that spanned roughly 12 years. The bug exists in PostgreSQL’s logical replication mechanism, which is commonly used for backup operations, standby databases, change data capture pipelines, migrations, monitoring, and analytics.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7. 2), has been present since logical decoding was introduced in PostgreSQL 9. 4 in 2014. Versions before PostgreSQL 18. 6, 17. 11, 16. 15, 15. 19, and 14. 24 are

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7. 2). Present in releases dating back to 2014, the flaw can be exploited by attackers with low-level replication access to execute code, escalate privileges and gain permanent superuser access. “Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin.” reads the advisory . “This in turn runs arbitrary code as that account. Versions before PostgreSQL 18. 6, 17. 11, 16. 15, 15. 19, and 14. 24 are affected.”

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Decade-old PostgreSQL flaw turns backup account into a backdoor

A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functionality and could allow an attacker with a low-privilege account carrying the REPLICATION attribute to load and execute arbitrary code. “The flaw lets a low-privilege “backup” account load and execute arbitrary code on the database server, achieving remote code execution across Windows, Linux, and macOS,” said Cyera researcher Vladimir Tokarev in a blog post. “That foothold escalates to full PostgreSQL superuser with persistent backdoor access, turning a routine replication account into total database and server compromise.” The vulnerability, tracked as CVE-2026-6471, affects PostgreSQL versions dating back to 9.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8. 8. The following CVEs are assigned: CVE-2026-64715.

·Zero Day Initiative (Published)
Read →

You've reached the end of current stories for this search.