bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, September 24, 2026

Critical RCE Vulnerability in AWS pgcollection – Immediate Action Required

AWS pgcollection (PostgreSQL extension) versions 2.0.0–2.1.1 have a type confusion bug (CVE-2026-96883) that lets authenticated database users crash the backend or run arbitrary code. The vulnerability stems from improper type coercion when requesting stored icollection values as incompatible types. If you're running affected versions, update immediately to patch this important security issue.

source: [aws/security-bulletin]