PatchSiren cyber security CVE debrief
CVE-2026-60623 Oracle Corporation CVE debrief
A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/J component. The vulnerability has a CVSS score of 7.1 and can allow a low-privileged attacker with network access to compromise MySQL Connectors, potentially leading to unauthorized data access, modification, and partial denial of service. This vulnerability affects versions 9.7.0-9.7.1 and has a CVSS Vector of (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L). System administrators and security teams should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-07-21T22:18:02.830Z and was last modified on 2026-07-25T05:16:41.547Z.
- Vendor
- Oracle Corporation
- Product
- MySQL Connectors
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-09-03
Who should care
System administrators and security teams responsible for MySQL Connectors, particularly those using versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability in MySQL Connectors (component: Connector/J) affects versions 9.7.0-9.7.1. It is difficult to exploit and requires a low-privileged attacker with network access via multiple protocols. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all MySQL Connectors accessible data, as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. The CVSS 3.1 Base Score is 7.1 (Confidentiality, Integrity, and Availability impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
Defensive priority
High priority should be given to patching or mitigating this vulnerability, especially in environments where MySQL Connectors are exposed to the network.
Recommended defensive actions
- Apply the latest patches or updates for MySQL Connectors to version 9.7.2 or later.
- Restrict network access to MySQL Connectors to only necessary personnel and services.
- Monitor MySQL Connectors logs for suspicious activity.
- Consider implementing additional security measures such as encryption and access controls.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:18:02.830Z and was last modified on 2026-07-25T05:16:41.547Z. The NVD entry is currently Awaiting Analysis. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60623 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60623
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60623 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60623
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.