Post

Critical Vulnerability CVE-2026-60324 in MySQL Server

Critical Vulnerability CVE-2026-60324 in MySQL Server

Critical Vulnerability CVE-2026-60324 in MySQL Server

CVE-2026-60324 has been identified as a critical vulnerability in the MySQL Server and MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). The supported versions currently affected are MySQL Server: 9.7.0-9.7.1 and MySQL Cluster: 9.7.0-9.7.1. This is an easily exploitable vulnerability, allowing a low privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash, leading to a complete Denial of Service (DOS) of MySQL Server and MySQL Cluster instances. 🚨

The vulnerability has been assigned a CVSS 3.1 Base Score of 6.5, with availability impacts. The full CVSS Vector is specified as: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). In terms of affected products, the report states: “The following products are affected by CVE-2026-60324 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.”

Cybersecurity researchers actively scan GitHub repositories to detect new proof-of-concept exploits related to this CVE. A comprehensive list details a collection of public exploits and proof-of-concepts, which have been published on GitHub, sorted by the most recently updated. It is important to note that results are limited to the first 15 repositories due to potential performance issues during scanning. 🔍

The vulnerability’s timeline shows that the following table lists the changes that have been made to the CVE-2026-60324 vulnerability over time. Understanding vulnerability history details can be highly useful for understanding the evolution of a vulnerability and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. A new CVE was officially received on July 21, 2026. For complete and up-to-date information, please consult the official reference URL: Oracle Security Alerts.

To read the complete article see: CVE-2026-60324 Details

This post is licensed under CC BY 4.0 by the author.