CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0262 [1.00] [M/H] Vulnerabilities fixed in Oracle MySQL Server and MySQL Cluster

unknownCVE-2026-46936CVE-2026-47008CVE-2026-47012CVE-2026-47023CVE-2026-47052CVE-2026-47064
Oracle has fixed multiple vulnerabilities in Oracle MySQL Server and MySQL Cluster. The vulnerabilities affect various versions of Oracle MySQL Server and MySQL Cluster. Some vulnerabilities allow an attacker with high privileges and network access to cause a denial-of-service (DoS), potentially hanging or crashing the server, affecting the availability of the database. Some DoS vulnerabilities can also be exploited by low-privileged users. Additionally, there are vulnerabilities in the Group Replication Plugin and the NDB Operator component that may allow DoS or unauthorized access to data. Furthermore, there are vulnerabilities that enable an attacker with high privileges and network access to gain full control over the server, impacting confidentiality, integrity, and availability. There are also vulnerabilities in Oracle MySQL Connectors (Connector/C++, Connector/Net, Connector/J) that allow unauthenticated or low-privileged attackers with network access to manipulate data, gain access to sensitive information, or cause a denial-of-service. Some vulnerabilities require user interaction or local access. The CVSS 3.1 scores range from low (2.2) to high (8.5), depending on the type of vulnerability and the impact on the systems. The vulnerabilities are specific to Oracle MySQL Server, MySQL Cluster, and the MySQL Connectors, and are exploitable via network access, sometimes with additional requirements such as infrastructure access, user interaction, or local access.

CSIRTS triage

What
The vulnerabilities can cause denial-of-service and unauthorized access to data.
Who is affected
Various versions of Oracle MySQL Server and MySQL Cluster installations.
Urgency
Remediation is important as some vulnerabilities can be exploited by low-privileged users.
Action
Update to the latest versions of Oracle MySQL Server and MySQL Cluster.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch MySQL Server and MySQL Cluster

Get an email when a new MySQL Server and MySQL Cluster advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0262

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-46936coverage & exploitation statusNVD · CVE.org
CVE-2026-47008coverage & exploitation statusNVD · CVE.org
CVE-2026-47012coverage & exploitation statusNVD · CVE.org
CVE-2026-47023coverage & exploitation statusNVD · CVE.org
CVE-2026-47052coverage & exploitation statusNVD · CVE.org
CVE-2026-47064coverage & exploitation statusNVD · CVE.org
CVE-2026-60145coverage & exploitation statusNVD · CVE.org
CVE-2026-60163coverage & exploitation statusNVD · CVE.org
CVE-2026-60171coverage & exploitation statusNVD · CVE.org
CVE-2026-60174coverage & exploitation statusNVD · CVE.org
CVE-2026-60177coverage & exploitation statusNVD · CVE.org
CVE-2026-60178coverage & exploitation statusNVD · CVE.org
CVE-2026-60179coverage & exploitation statusNVD · CVE.org
CVE-2026-60180coverage & exploitation statusNVD · CVE.org
CVE-2026-60181coverage & exploitation statusNVD · CVE.org
CVE-2026-60182coverage & exploitation statusNVD · CVE.org
CVE-2026-60183coverage & exploitation statusNVD · CVE.org
CVE-2026-60184coverage & exploitation statusNVD · CVE.org
CVE-2026-60185coverage & exploitation statusNVD · CVE.org
CVE-2026-60186coverage & exploitation statusNVD · CVE.org
CVE-2026-60187coverage & exploitation statusNVD · CVE.org
CVE-2026-60188coverage & exploitation statusNVD · CVE.org
CVE-2026-60189coverage & exploitation statusNVD · CVE.org
CVE-2026-60190coverage & exploitation statusNVD · CVE.org
CVE-2026-60191coverage & exploitation statusNVD · CVE.org
CVE-2026-60192coverage & exploitation statusNVD · CVE.org
CVE-2026-60193coverage & exploitation statusNVD · CVE.org
CVE-2026-60194coverage & exploitation statusNVD · CVE.org
CVE-2026-60195coverage & exploitation statusNVD · CVE.org
CVE-2026-60311coverage & exploitation statusNVD · CVE.org
CVE-2026-60314coverage & exploitation statusNVD · CVE.org
CVE-2026-60315coverage & exploitation statusNVD · CVE.org
CVE-2026-60316coverage & exploitation statusNVD · CVE.org
CVE-2026-60317coverage & exploitation statusNVD · CVE.org
CVE-2026-60324coverage & exploitation statusNVD · CVE.org
CVE-2026-60331coverage & exploitation statusNVD · CVE.org
CVE-2026-60332coverage & exploitation statusNVD · CVE.org
CVE-2026-60569coverage & exploitation statusNVD · CVE.org
CVE-2026-60585coverage & exploitation statusNVD · CVE.org
CVE-2026-60586coverage & exploitation statusNVD · CVE.org
CVE-2026-60623coverage & exploitation statusNVD · CVE.org
CVE-2026-60624coverage & exploitation statusNVD · CVE.org
CVE-2026-60718coverage & exploitation statusNVD · CVE.org
CVE-2026-60725coverage & exploitation statusNVD · CVE.org
CVE-2026-60747coverage & exploitation statusNVD · CVE.org
CVE-2026-61081coverage & exploitation statusNVD · CVE.org
CVE-2026-61082coverage & exploitation statusNVD · CVE.org
CVE-2026-61093coverage & exploitation statusNVD · CVE.org

+6 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories