PatchSiren cyber security CVE debrief
CVE-2026-60623 Oracle Corporation CVE debrief
A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/J component. The vulnerability has a CVSS score of 7.1 and can allow a low-privileged attacker with network access to compromise MySQL Connectors, potentially leading to unauthorized data access, modification, and partial denial of service. This vulnerability affects versions 9.7.0-9.7.1 and has a CVSS Vector of (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). System administrators and security teams should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-07-21T22:18:02.830Z and was last modified on 2026-07-25T05:16:41.547Z.
- Vendor
- Oracle Corporation
- Product
- MySQL Connectors
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-25
Who should care
System administrators and security teams responsible for MySQL Connectors, particularly those using versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability in MySQL Connectors (component: Connector/J) affects versions 9.7.0-9.7.1. It is difficult to exploit and requires a low-privileged attacker with network access via multiple protocols. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data, as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. The CVSS 3.1 Base Score is 7.1 (Confidentiality, Integrity, and Availability impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
Defensive priority
High priority should be given to patching or mitigating this vulnerability, especially in environments where MySQL Connectors are exposed to the network.
Recommended defensive actions
- Apply the latest patches or updates for MySQL Connectors to version 9.7.2 or later.
- Restrict network access to MySQL Connectors to only necessary personnel and services.
- Monitor MySQL Connectors logs for suspicious activity.
- Consider implementing additional security measures such as encryption and access controls.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:18:02.830Z and was last modified on 2026-07-25T05:16:41.547Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).
Official resources
-
CVE-2026-60623 CVE record
CVE.org
-
CVE-2026-60623 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:02.830Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.