PatchSiren cyber security CVE debrief
CVE-2026-60193 Oracle Corporation CVE debrief
A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/Net component. The vulnerability has a CVSS score of 8.5 and can be exploited by a low-privileged attacker with network access via multiple protocols, potentially leading to a takeover of MySQL Connectors and impacting additional products. This vulnerability is difficult to exploit and requires a low-privileged attacker with network access via multiple protocols. The affected versions are 9.7.0-9.7.1. Successful attacks can result in a takeover of MySQL Connectors and significantly impact additional products.
- Vendor
- Oracle Corporation
- Product
- MySQL Connectors
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-25
Who should care
Organizations using MySQL Connectors, especially versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes inventory and assessment of affected versions, applying patches or updates provided by Oracle, implementing network access controls, monitoring for suspicious activity, and considering compensating controls. Affected operators, platforms, and security teams should prioritize this vulnerability due to its high severity and potential impact.
Technical summary
The vulnerability is in the MySQL Connectors product of Oracle MySQL, specifically in the Connector/Net component. Supported versions that are affected are 9.7.0-9.7.1. It is a difficult-to-exploit vulnerability that allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in a takeover of MySQL Connectors. The CVSS 3.1 Base Score is 8.5, with impacts on Confidentiality, Integrity, and Availability.
Defensive priority
High
Recommended defensive actions
- Inventory and assess MySQL Connectors versions 9.7.0-9.7.1 for potential vulnerability
- Apply patches or updates provided by Oracle to fix the vulnerability
- Implement network access controls to limit access to MySQL Connectors
- Monitor MySQL Connectors for suspicious activity
- Consider compensating controls, such as additional authentication or authorization mechanisms
Evidence notes
The CVE record was published on 2026-07-21T22:17:20.497Z and was last modified on 2026-07-25T05:16:36.060Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability. Further verification is needed to confirm the affected scope and severity. Defenders should review the official advisory and track exceptions for exposed systems.
Official resources
-
CVE-2026-60193 CVE record
CVE.org
-
CVE-2026-60193 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:20.497Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.