PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60193 Oracle Corporation CVE debrief

A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/Net component. The vulnerability has a CVSS score of 8.5 and can be exploited by a low-privileged attacker with network access via multiple protocols, potentially leading to a takeover of MySQL Connectors and impacting additional products. This vulnerability is difficult to exploit and requires a low-privileged attacker with network access via multiple protocols. The affected versions are 9.7.0-9.7.1. Successful attacks can result in a takeover of MySQL Connectors and significantly impact additional products.

Vendor
Oracle Corporation
Product
MySQL Connectors
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-25
Advisory published
2026-07-21
Advisory updated
2026-07-25

Who should care

Organizations using MySQL Connectors, especially versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes inventory and assessment of affected versions, applying patches or updates provided by Oracle, implementing network access controls, monitoring for suspicious activity, and considering compensating controls. Affected operators, platforms, and security teams should prioritize this vulnerability due to its high severity and potential impact.

Technical summary

The vulnerability is in the MySQL Connectors product of Oracle MySQL, specifically in the Connector/Net component. Supported versions that are affected are 9.7.0-9.7.1. It is a difficult-to-exploit vulnerability that allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in a takeover of MySQL Connectors. The CVSS 3.1 Base Score is 8.5, with impacts on Confidentiality, Integrity, and Availability.

Defensive priority

High

Recommended defensive actions

  • Inventory and assess MySQL Connectors versions 9.7.0-9.7.1 for potential vulnerability
  • Apply patches or updates provided by Oracle to fix the vulnerability
  • Implement network access controls to limit access to MySQL Connectors
  • Monitor MySQL Connectors for suspicious activity
  • Consider compensating controls, such as additional authentication or authorization mechanisms

Evidence notes

The CVE record was published on 2026-07-21T22:17:20.497Z and was last modified on 2026-07-25T05:16:36.060Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm the affected scope and severity. Defenders should review the official advisory and track exceptions for exposed systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:20.497Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.