NCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL
Oracle has resolved vulnerabilities in Oracle MySQL Cluster and Oracle MySQL Connector/ODBC. Oracle MySQL Cluster versions 8.0.0 through 8.0.48, 8.4.0 through 8.4.11 and 9.7.0 through 9.7.2 contain vulnerabilities that allow an unauthenticated external attacker via network access to cause denial of service, perform unauthorized data modification or take over the system, with some misuse requiring user interaction. Oracle MySQL Connector/ODBC version 26.7.0 contains multiple vulnerabilities that allow an unauthenticated attacker with infrastructure access and sometimes user interaction to cause denial of service through crashes, and in some cases obtain unauthorized read access to data, affecting availability and confidentiality.
CSIRTS triage
- What
- Vulnerabilities in Oracle MySQL Cluster and Connector/ODBC allow denial of service, unauthorized data modification, system takeover, and information disclosure.
- Who is affected
- Deployments running the specified versions of MySQL Cluster and Connector/ODBC.
- Urgency
- High urgency; allows unauthenticated remote attacks resulting in system compromise and data breach.
- Action
- Upgrade MySQL Cluster to patched versions and update MySQL Connector/ODBC to a fixed release.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MySQL Cluster and MySQL Connector/ODBC
Get an email when a new MySQL Cluster and MySQL Connector/ODBC advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0315
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2025-131511.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-148210.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-09680.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-605920.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-659140.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-707240.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710730.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710790.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710840.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-13151 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-14821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0968 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60592 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65914 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70724 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71073 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71079 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71084 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communicationsncsc-nl
- high[NEW] [HIGH] Oracle Communications: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle MySQL: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- mediumCVE-2026-71084: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The…nvd
- mediumCVE-2026-71079: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The…nvd
- mediumCVE-2026-71073: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The…nvd
- highCVE-2026-70724: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supp…nvd
- highCVE-2026-60592: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator).…nvd
- medium[UPDATE] [medium] libtasn1: Vulnerability allows Denial of Servicecert-bund
- medium[UPDATE] [medium] libssh: Multiple vulnerabilities enable file manipulation and DoScert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Or…2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Manager2026-08-19