PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61093 Oracle Corporation CVE debrief

A vulnerability exists in MySQL Server and MySQL Cluster products of Oracle MySQL. The vulnerability is located in the Server: Optimizer component and affects versions 9.7.0-9.7.1 of both products. A low-privileged attacker with network access via multiple protocols can exploit this vulnerability to compromise MySQL Server and MySQL Cluster, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 6.5, indicating a medium severity level.

Vendor
Oracle Corporation
Product
MySQL Server
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

System administrators and security teams responsible for MySQL Server and MySQL Cluster installations, particularly those using versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

A vulnerability exists in the Server: Optimizer component of MySQL Server and MySQL Cluster products of Oracle MySQL, affecting versions 9.7.0-9.7.1. This weakness allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 6.5, indicating a medium severity level, with the CVSS vector being CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified under CWE-400. System administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential denial-of-service attacks.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it can be exploited by low-privileged attackers to cause a denial of service.

Recommended defensive actions

  • Apply the patches or updates provided by Oracle to fix the vulnerability
  • Restrict network access to MySQL Server and MySQL Cluster to only necessary personnel
  • Monitor MySQL Server and MySQL Cluster installations for any suspicious activity
  • Consider implementing compensating controls, such as web application firewalls or intrusion detection systems
  • Review and update asset inventory to identify potentially affected systems
  • Perform exposure review to assess potential impact on the organization
  • Track changes and updates to affected systems and CVE details

Evidence notes

The CVE record was published on 2026-07-21T22:18:40.333Z and was last modified on 2026-07-27T17:49:21.220Z. The NVD entry is currently Analyzed. The vulnerability is described in the Oracle Security Alert for July 2026.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:40.333Z and has not been modified since then. The NVD entry is currently Analyzed.