LIVE · cybersecurity feed
Live wire
CVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No Patch
CVE-2026-6471

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 2014, the flaw can be exploited by attackers with low-level replication access to execute code, […]

zeroday.news ·

A critical vulnerability, dubbed "PostGREShell" and tracked as CVE-2026-6471, has been discovered in PostgreSQL, allowing low-privileged attackers to execute arbitrary code and potentially take over database servers. The flaw, which has a CVSS score of 7.2, has been present in all PostgreSQL versions since 9.4, released in 2014, and remained unpatched for 12 years until recent updates.

The vulnerability stems from a missing authorization check within PostgreSQL's logical decoding feature. An attacker with only "Replication" privileges can exploit this by manipulating the choice of a logical decoding plugin. This allows them to load any file accessible to the operating system account running the PostgreSQL server, effectively executing arbitrary code as that account.

According to researchers at Cyera, who discovered the flaw, the issue enables a low-privilege backup account to achieve remote code execution across Windows, Linux, and macOS systems. This initial foothold can then be escalated to full PostgreSQL superuser privileges, providing persistent backdoor access and leading to a complete compromise of the database and the underlying server. Attackers could install a persistent backdoor, access all tables in every database, execute operating system commands, read private keys, and write files anywhere the PostgreSQL process has access.

PostgreSQL's logical replication system is designed to keep database replicas synchronized for backup and recovery purposes. Tools, servers, data pipelines, and monitoring systems often require accounts with "Replication" privileges to function. The vulnerability leverages the process by which PostgreSQL loads output plugins during logical replication. Normally, non-superusers are restricted to loading plugins from administrator-controlled directories. However, the system does not properly validate the plugin name provided by the user during the `CREATE_REPLICATION_SLOT` command, passing it directly to the `dlopen()` function (on Linux/macOS) or `LoadLibrary()` (on Windows). This allows an attacker to specify a full filesystem path to an arbitrary file.

The flaw affects PostgreSQL versions 9.4 through 18. PostgreSQL has confirmed the vulnerability and released patches in versions 18.6, 17.11, 16.15, 15.19, and 14.24. Organizations are strongly advised to update their PostgreSQL instances immediately. Additionally, it is recommended to review all existing "Replication" accounts and remove the "Replication" attribute from any accounts that do not strictly require it to minimize the attack surface.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-14894critical

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

ai

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

breach

Russian data centers face new security requirements amid Ukraine's drone threats

Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.

nation-state

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition