PatchSiren cyber security CVE debrief
CVE-2026-60186 Oracle Corporation CVE debrief
A vulnerability was discovered in the MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: Group Replication Plugin component. The affected versions are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. This difficult-to-exploit vulnerability allows high-privileged attackers with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server and MySQL Cluster.
- Vendor
- Oracle Corporation
- Product
- MySQL Server
- CVSS
- MEDIUM 4.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
System administrators and security teams responsible for MySQL Server and MySQL Cluster installations, particularly those using versions 8.4.0-8.4.10, 9.7.0-9.7.1, 8.0.0-8.0.47, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability has a CVSS 3.1 Base Score of 4.4 (Availability impacts) and a CVSS Vector of (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). It is classified as a difficult-to-exploit vulnerability that allows high-privileged attackers with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially leading to a denial of service (DOS). The affected versions are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. System administrators and security teams should focus on patching and mitigating this vulnerability.
Defensive priority
Medium priority should be given to patching this vulnerability, as it can lead to a complete DOS of MySQL Server and MySQL Cluster, and is considered difficult to exploit but still poses a risk.
Recommended defensive actions
- Apply the patches provided by Oracle as soon as possible
- Review and update MySQL Server and MySQL Cluster installations to ensure they are running on a supported and patched version
- Implement compensating controls such as monitoring and intrusion detection systems to detect potential exploitation attempts
- Limit network access to MySQL Server and MySQL Cluster to only necessary personnel and systems
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-21T22:17:19.647Z and was last modified on 2026-07-27T17:33:52.237Z. The NVD entry is currently Analyzed. Evidence is limited, and defenders should verify MySQL Server and MySQL Cluster installations, especially versions 8.4.0-8.4.10, 9.7.0-9.7.1, 8.0.0-8.0.47.
Official resources
-
CVE-2026-60186 CVE record
CVE.org
-
CVE-2026-60186 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:19.647Z and has not been modified since then. The NVD entry is currently Analyzed.