CVE-2026-14676
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running
CVSS
8.8
High
EPSS
0.4%
p35
KEV
—
Exploit Today
11
0-100
Published: Aug 13, 2026 · Last modified: Aug 29, 2026 · CWE-122
0.4%EPSS · 30 days0.4%
2026-08-272026-09-24
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-97152—21.5%
——6Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.21hCVE-2026-869267.8 HIG4.1%
——1A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.1dCVE-2026-756657.8 HIG8.6%
——3Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.2dCVE-2026-756497.8 HIG7.2%
——2Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.21hCVE-2026-18457—15.4%
——5Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*.3dCVE-2026-941279.8 CRI69.0%
KEV—71F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability2d