CVE-2026-49458
Multiple vulnerabilities have been discovered in Oracle MySQL. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle MySQL allow remote code execution, denial of service, and data confidentiality breaches.
- Who is affected
- Deployments running affected versions of Oracle MySQL are vulnerable.
- Urgency
- Remediation is urgent due to the presence of remote code execution capabilities; however, specific affected versions are not detailed.
- Action
- Identify and upgrade to patched versions of Oracle MySQL as released by Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-49458
Get an email if CVE-2026-49458 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis · 2026-08-19
- mediumCVE-2026-49458: DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4…nvd · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-49458)