PatchSiren cyber security CVE debrief
CVE-2026-60314 Oracle Corporation CVE debrief
The CVE-2026-60314 vulnerability affects the MySQL Router product of Oracle MySQL, specifically the Router: General component. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. This vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Users and administrators should verify MySQL Router versions, review vendor advisories, and implement compensating controls to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.
- Vendor
- Oracle Corporation
- Product
- MySQL Router
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
Users of MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes verifying MySQL Router versions, reviewing vendor advisories, and implementing compensating controls. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take appropriate actions to protect their systems.
Technical summary
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. The vulnerability has a high CVSS score of 7.5 and a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
High priority due to high CVSS score of 7.5 and potential for complete DOS of MySQL Router.
Recommended defensive actions
- Inventory and verify MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1 are not in use or apply vendor patches
- Implement compensating controls such as network access restrictions
- Monitor for potential DOS attacks
- Exception tracking for MySQL Router instances
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence from official vulnerability database and vendor advisory indicate vulnerability in MySQL Router product of Oracle MySQL. Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router, potentially causing a hang or frequently repeatable crash (complete DOS) of MySQL Router. Defenders should verify MySQL Router versions, review vendor advisories, and implement compensating controls.
Official resources
-
CVE-2026-60314 CVE record
CVE.org
-
CVE-2026-60314 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:34.173Z and has not been modified since then.