PatchSiren cyber security CVE debrief
CVE-2026-61093 Oracle Corporation CVE debrief
A vulnerability exists in MySQL Server and MySQL Cluster products of Oracle MySQL. The vulnerability is located in the Server: Optimizer component and affects versions 9.7.0-9.7.1 of both products. A low-privileged attacker with network access via multiple protocols can exploit this vulnerability to compromise MySQL Server and MySQL Cluster, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 6.5, indicating a medium severity level.
- Vendor
- Oracle Corporation
- Product
- MySQL Server
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
System administrators and security teams responsible for MySQL Server and MySQL Cluster installations, particularly those using versions 9.7.0-9.7.1, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
A vulnerability exists in the Server: Optimizer component of MySQL Server and MySQL Cluster products of Oracle MySQL, affecting versions 9.7.0-9.7.1. This weakness allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 6.5, indicating a medium severity level, with the CVSS vector being CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified under CWE-400. System administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential denial-of-service attacks.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, as it can be exploited by low-privileged attackers to cause a denial of service.
Recommended defensive actions
- Apply the patches or updates provided by Oracle to fix the vulnerability
- Restrict network access to MySQL Server and MySQL Cluster to only necessary personnel
- Monitor MySQL Server and MySQL Cluster installations for any suspicious activity
- Consider implementing compensating controls, such as web application firewalls or intrusion detection systems
- Review and update asset inventory to identify potentially affected systems
- Perform exposure review to assess potential impact on the organization
- Track changes and updates to affected systems and CVE details
Evidence notes
The CVE record was published on 2026-07-21T22:18:40.333Z and was last modified on 2026-07-27T17:49:21.220Z. The NVD entry is currently Analyzed. The vulnerability is described in the Oracle Security Alert for July 2026.
Official resources
-
CVE-2026-61093 CVE record
CVE.org
-
CVE-2026-61093 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:40.333Z and has not been modified since then. The NVD entry is currently Analyzed.