PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60190 Oracle Corporation CVE debrief

A vulnerability exists in MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: Replication component. The vulnerability is difficult to exploit and allows high-privileged attackers with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful attacks can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server and MySQL Cluster. The CVSS 3.1 Base Score is 2.2 (Availability impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L). Administrators and users should be aware of this vulnerability and take necessary precautions.

Vendor
Oracle Corporation
Product
MySQL Server
CVSS
LOW 2.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Administrators and users of MySQL Server and MySQL Cluster products, especially those with high privileges, should be aware of this vulnerability and take necessary precautions. This includes reviewing system configurations, ensuring proper access controls are in place, and monitoring for any suspicious activity related to MySQL Server and MySQL Cluster. Additionally, security teams should prioritize patching and mitigation efforts based on the organization's risk tolerance and the potential impact on business operations.

Technical summary

The vulnerability is located in the Server: Replication component of MySQL Server and MySQL Cluster. Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. The CVSS 3.1 Base Score is 2.2 (Availability impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L). The vulnerability allows high-privileged attackers with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially leading to a partial denial of service (partial DOS). Administrators should focus on compensating controls and monitoring due to the difficulty in exploitation and lower CVSS score.

Defensive priority

Low to Moderate, given the high privilege requirement and partial DOS impact, with a focus on compensating controls and monitoring due to the difficulty in exploitation and lower CVSS score, but still a priority for high-privileged systems and networks, especially in environments where MySQL Server and MySQL Cluster are critical, and consider implementing additional security measures to reduce the attack surface and improve detection capabilities for potential exploitation attempts, considering the potential impact on data integrity and availability, and ensuring that incident response plans are in place to address potential breaches quickly and effectively, and reviewing and updating security policies and procedures to reflect the current threat landscape and best practices for securing MySQL Server and MySQL Cluster deployments, and taking into account the potential for lateral movement and escalation of privileges in the event of a successful exploit, and ensuring that security teams are aware of the vulnerability and its potential impact on the organization's assets and operations, and prioritizing patching and mitigation efforts based on the organization's risk tolerance and the potential impact on business operations, and considering the implementation of additional security controls, such as network segmentation and access controls, to reduce the attack surface and improve detection capabilities, and ensuring that security teams have the necessary skills and resources to effectively manage and respond to potential security incidents related to this vulnerability, and reviewing and updating incident response plans to ensure they are effective in addressing potential breaches related to this vulnerability, and taking into account the potential for reputational damage and financial loss in the event of a successful exploit, and prioritizing communication and collaboration with stakeholders, including customers, partners, and regulators, to ensure that they are aware of the vulnerability and its potential impact, and to coordinate response and mitigation efforts as needed, and ensuring that security teams are aware of the potential for exploitation and are in

Recommended defensive actions

  • Inventory and verify MySQL Server and MySQL Cluster versions
  • Apply vendor patches or updates
  • Monitor for suspicious activity
  • Implement compensating controls
  • Restrict network access to MySQL Server and MySQL Cluster

Evidence notes

The CVE record was published on 2026-07-21T22:17:20.157Z and was last modified on 2026-07-27T17:16:56.040Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects MySQL Server and MySQL Cluster products of Oracle MySQL. The evidence is limited, and defenders should verify the affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:20.157Z and has not been modified since then. The NVD entry is currently Analyzed.