Jul 30, 2026 · Subject: ClickHouse RCE (9.1) + 3 PCP flaws worth checking
ClickHouse SQLi hits 9.1, PCP ships four bugs including a root privesc chain
No zero-days today, but don't sleepwalk through this one. A CVSS 9.1 SQL injection in ClickHouse Server lets a remote attacker get code execution with minimal effort, and three separate PCP bugs chain together in ugly ways if your metrics infrastructure is exposed. None are exploited in the wild yet, so you've got time to be deliberate, but not to ignore them.
One item / urgency verdict
CVE-2026-16524
An attacker who can set the network.persocket.filter metric in PCP's linux_sockets PMDA can inject shell commands that run as the PMDA user whenever metrics refresh.
Update PCP to the latest patched release from your distro's package manager, or disable the linux_sockets PMDA until a fix is available.