PatchSiren cyber security CVE debrief
CVE-2026-60314 Oracle Corporation CVE debrief
The CVE-2026-60314 vulnerability affects the MySQL Router product of Oracle MySQL, specifically the Router: General component. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. This vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Users and administrators should verify MySQL Router versions, review vendor advisories, and implement compensating controls to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.
- Vendor
- Oracle Corporation
- Product
- MySQL Router
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
Users of MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.
Technical summary
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
High priority due to high CVSS score of 7.5 and potential for complete DOS of MySQL Router.
Recommended defensive actions
- Inventory and verify MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 are not in use or apply vendor patches
- Implement compensating controls such as network access restrictions
- Monitor for potential DOS attacks
- Exception tracking for MySQL Router instances
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence from official vulnerability database and vendor advisory indicate vulnerability in MySQL Router product of Oracle MySQL. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router, potentially causing a hang or frequently repeatable crash (complete DOS) of MySQL Router. Defenders should verify MySQL Router versions, review vendor advisories, and implement compensating controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60314 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60314
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60314 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60314
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.