CVE-2026-65903
Multiple vulnerabilities have been discovered in Oracle MySQL. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle MySQL allow remote code execution, denial of service, and data confidentiality breaches.
- Who is affected
- Deployments running affected versions of Oracle MySQL are vulnerable.
- Urgency
- Remediation is urgent due to the presence of remote code execution capabilities; however, specific affected versions are not detailed.
- Action
- Identify and upgrade to patched versions of Oracle MySQL as released by Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-65903
Get an email if CVE-2026-65903 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Advisory coverage (3)
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis · 2026-08-19
- mediumCVE-2026-65903: DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit eva…nvd · 2026-07-23
- mediumGHSA-39q2-94rc-95cp: DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluationghsa · 2026-04-16
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-65903)