<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh" -->

---
title: PostgreSQL SQL Injection Vulnerability Exploited...
description: Critical vulnerabilities in PostgreSQL and BeyondTrust products have been exploited in targeted attacks, prompting urgent security updates. The exploits...
canonical: https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: PostgreSQL SQL Injection Vulnerability Exploited Alongside BeyondTrust Zero-Day | daily.dev
og:description: Critical vulnerabilities in PostgreSQL and BeyondTrust products have been exploited in targeted attacks, prompting urgent security updates. The exploits...
og:url: https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh
og:image: https://api.daily.dev/og/posts/1Yr1MKfXH.png
og:image:alt: PostgreSQL SQL Injection Vulnerability Exploited Alongside BeyondTrust Zero-Day
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# PostgreSQL SQL Injection Vulnerability Exploited Alongside BeyondTrust Zero-Day

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Critical vulnerabilities in PostgreSQL and BeyondTrust products have been exploited in targeted attacks, prompting urgent security updates. The exploits involved CVE-2024-12356 and CVE-2025-1094 for remote code execution. Users are strongly advised to update to the latest versions to protect against these risks.

## Content

### Overview

A recent investigation has uncovered a series of targeted attacks that leveraged critical vulnerabilities in PostgreSQL and BeyondTrust products. Attackers exploited these flaws to achieve remote code execution, prompting urgent updates from software maintainers.

### Vulnerabilities and Exploits

Rapid7 researchers identified the exploit chain, which required both CVE-2024-12356 and the newly discovered CVE-2025-1094 vulnerabilities for remote code execution. The former existed within BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products, while the latter was a high-severity SQL injection bug in PostgreSQL. These flaws played a crucial role in the attack against the US Treasury.

Further investigation revealed that despite recent patches for PostgreSQL, the root cause of CVE-2025-1094 had not been fully addressed until now. The PostgreSQL maintainers have since released updates for versions 13 to 17 to mitigate the vulnerabilities.

### Recommended Actions

To protect against these threats, users of PostgreSQL and BeyondTrust products are strongly advised to update to the latest versions. The updated versions contain additional sanitization checks to prevent such exploits and ensure secure operation.

Furthermore, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-57727, a flaw in SimpleHelp remote support software, to its Known Exploited Vulnerabilities catalog. Administrators should also apply relevant patches for affected software.

### Conclusion

The discovery of these vulnerabilities and their exploitation underscores the importance of maintaining up-to-date security practices. Updating to the latest software versions and applying patches promptly can significantly mitigate risks associated with such security flaws.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#postgresql](https://daily.dev/tags/postgresql), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"PostgreSQL SQL Injection Vulnerability Exploited Alongside BeyondTrust Zero-Day","url":"https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh"},"datePublished":"2025-02-14T05:18:58.262Z","dateModified":"2025-02-14T14:28:07.164Z","description":"Critical vulnerabilities in PostgreSQL and BeyondTrust products have been exploited in targeted attacks, prompting urgent security updates. The exploits...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e4c61555ed02fbb773feee87f478172b?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e4c61555ed02fbb773feee87f478172b?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/postgresql-sql-injection-vulnerability-exploited-alongside-beyondtrust-zero-day-1yr1mkfxh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,postgresql,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"PostgreSQL SQL Injection Vulnerability Exploited Alongside BeyondTrust Zero-Day"}]}
```

