PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60314 Oracle Corporation CVE debrief

The CVE-2026-60314 vulnerability affects the MySQL Router product of Oracle MySQL, specifically the Router: General component. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. This vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Users and administrators should verify MySQL Router versions, review vendor advisories, and implement compensating controls to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.

Vendor
Oracle Corporation
Product
MySQL Router
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-28
Advisory published
2026-07-21
Advisory updated
2026-07-28

Who should care

Users of MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.

Technical summary

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Defensive priority

High priority due to high CVSS score of 7.5 and potential for complete DOS of MySQL Router.

Recommended defensive actions

  • Inventory and verify MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 are not in use or apply vendor patches
  • Implement compensating controls such as network access restrictions
  • Monitor for potential DOS attacks
  • Exception tracking for MySQL Router instances
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official vulnerability database and vendor advisory indicate vulnerability in MySQL Router product of Oracle MySQL. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router, potentially causing a hang or frequently repeatable crash (complete DOS) of MySQL Router. Defenders should verify MySQL Router versions, review vendor advisories, and implement compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:34.173Z and has not been modified since then.