pgAdmin 4 version 9.16 has been released, featuring 64 bug fixes and addressing seven security vulnerabilities (CVE-2026-12044 to CVE-2026-12050). Key vulnerabilities include SQL injection flaws and cross-site scripting issues. CVE-2026-12044 involved SQL injection risks in dialog templates, while CVE-2026-12045 allowed attackers to bypass read-only transaction restrictions in the AI Assistant feature. Authentication issues were fixed in CVE-2026-12046, and client-side vulnerabilities were addressed in CVE-2026-12048 and CVE-2026-12047. Additional vulnerabilities included an open redirect in multi-factor authentication (CVE-2026-12049) and another SQL injection flaw in restore point functionality (CVE-2026-12050). Usability improvements include colorized panel headers, middle-click tab closing, and enhancements to OAuth2 login. The release supports new PostgreSQL storage parameters and includes dependency upgrades. Stricter access controls have been enforced, and pgAgent has been marked for removal. The update is available for download on multiple platforms.