VORANT. Threat Intelligence Sign in Get the full feed

Oracle patches critical MySQL flaws enabling RCE

high vulnerability

Oracle released patches for multiple vulnerabilities in MySQL products affecting versions 8.0 through 9.7, including flaws enabling remote code execution and denial of service.

The French national cybersecurity agency CERT-FR has published an advisory concerning multiple vulnerabilities discovered in Oracle MySQL products. The flaws affect a wide range of MySQL components including MySQL Server, MySQL Cluster, MySQL NDB Cluster, MySQL Router, and MySQL Shell across versions 8.0.11 through 9.7.0. The vulnerabilities impact server connection handling, dump and load functionality, and the Shell for VS Code extension.

The security issues enable various attack vectors including remote code execution, remote denial of service, confidentiality breaches, and data integrity violations. Eight CVEs have been assigned to these vulnerabilities (CVE-2026-46850 through CVE-2026-46863, CVE-2026-46869 through CVE-2026-46871). Oracle has released patches as part of their June 2026 Critical Patch Update to address these security flaws.

Organizations running affected MySQL versions should consult Oracle's security bulletin and apply the available patches promptly. The broad version range affected suggests widespread exposure across database deployments in enterprise and cloud environments.

Mentioned in this report

Vulnerabilities CVE-2026-46850CVE-2026-46860CVE-2026-46861CVE-2026-46862CVE-2026-46863CVE-2026-46869CVE-2026-46870CVE-2026-46871

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0765

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free