ThreatCluster[verified]@threatclusterDisclosure
Announcement of a critical vulnerability in PgBouncer (CVE-2026-6664) that permits unauthenticated remote attackers to crash the service via malformed SCRAM authentication packets.
Upwind Security MDR[verified]@UpwindMDRPatch
The tweet highlights two high‑severity bugs in PgBouncer’s SCRAM handling and urges users to patch to version 1.25.2.
Euler Taveira@eulertoPatch
PgBouncer 1.25.2 release notes announce fixes for CVE-2026-6664, 6665, 6666, and 6667, indicating a patch was applied, but no additional technical details or exploitation evidence are presented.
CCB Alert@CCBalertActive Exploitation
CVE-2026-6664 describes a high integer overflow in PgBouncer that is being actively exploited by unauthenticated attackers, leading to system crashes; no patch details are provided.
CVEarity@CVEarityGeneral
The tweet announces CVE-2026-6664 with a severity score and general impact, but lacks technical, exploit, patch, or active exploitation details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-6664, describing an integer overflow in PgBouncer that leads to remote denial of service but provides no exploit code, patch information, or evidence of active attacks.