# Oracle patches critical MySQL flaws enabling RCE

Published: 2026-06-17 · Severity: high
Canonical: https://vorant.io/reports/991020af-83bd-5166-9cc1-44fd24e70d09/oracle-patches-critical-mysql-flaws-enabling-rce

> Oracle released patches for multiple vulnerabilities in MySQL products affecting versions 8.0 through 9.7, including flaws enabling remote code execution and denial of service.

The French national cybersecurity agency CERT-FR has published an advisory concerning multiple vulnerabilities discovered in Oracle MySQL products. The flaws affect a wide range of MySQL components including MySQL Server, MySQL Cluster, MySQL NDB Cluster, MySQL Router, and MySQL Shell across versions 8.0.11 through 9.7.0. The vulnerabilities impact server connection handling, dump and load functionality, and the Shell for VS Code extension.

The security issues enable various attack vectors including remote code execution, remote denial of service, confidentiality breaches, and data integrity violations. Eight CVEs have been assigned to these vulnerabilities (CVE-2026-46850 through CVE-2026-46863, CVE-2026-46869 through CVE-2026-46871). Oracle has released patches as part of their June 2026 Critical Patch Update to address these security flaws.

Organizations running affected MySQL versions should consult Oracle's security bulletin and apply the available patches promptly. The broad version range affected suggests widespread exposure across database deployments in enterprise and cloud environments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-46850, CVE-2026-46860, CVE-2026-46861, CVE-2026-46862, CVE-2026-46863, CVE-2026-46869, CVE-2026-46870, CVE-2026-46871

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0765

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/991020af-83bd-5166-9cc1-44fd24e70d09/oracle-patches-critical-mysql-flaws-enabling-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
