Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026)
Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across various MySQL versions and related products. Affected products include MySQL Cluster, MySQL Server, and Oracle Enterprise Manager. Users are advised to refer to the Oracle security bulletin for available patches and updates.
Oracle has announced multiple vulnerabilities within its MySQL database system. These vulnerabilities could lead to data integrity issues, data confidentiality breaches, and denial-of-service attacks. The CERT-FR bulletin details a comprehensive list of CVEs associated with these flaws.
What happened
Multiple vulnerabilities exist within the MySQL ecosystem. These vulnerabilities span several versions of MySQL, including MySQL Cluster, MySQL Server, MySQL Connectors, MySQL Router, and Oracle Enterprise Manager for MySQL Database. The vulnerabilities allow for remote denial-of-service attacks, unauthorized data access, and potential data corruption. The CERT-FR bulletin highlights a substantial number of CVEs (Common Vulnerabilities and Exposures) associated with these issues, including CVE-2025-68161, CVE-2026-46936, CVE-2026-47008, CVE-2026-47012, CVE-2026-47023, CVE-2026-47052, CVE-2026-47064, CVE-2026-60145, CVE-2026-60163, CVE-2026-60171, CVE-2026-60174, CVE-2026-60177, CVE-2026-60178, CVE-2026-60179, CVE-2026-60180, CVE-2026-60181, CVE-2026-60182, CVE-2026-60183, CVE-2026-60184, CVE-2026-60185, CVE-2026-60186, CVE-2026-60187, CVE-2026-60188, CVE-2026-60189, CVE-2026-60190, CVE-2026-60191, CVE-2026-60192, CVE-2026-60193, CVE-2026-60194, CVE-2026-60195, CVE-2026-60311, CVE-2026-60314, CVE-2026-60315, CVE-2026-60316, CVE-2026-60317, CVE-2026-60324, CVE-2026-60331, CVE-2026-60332, CVE-2026-60569, CVE-2026-60585, CVE-2026-60586, CVE-2026-60623, CVE-2026-60624, CVE-2026-60718, CVE-2026-60725, CVE-2026-60747, CVE-2026-61081, CVE-2026-61082, CVE-2026-61093, CVE-2026-61094, CVE-2026-61096, CVE-2026-61108, CVE-2026-61109, CVE-2026-61128, CVE-2026-61144.
Technical details
- **Affected Products:** MySQL Cluster, MySQL Server, MySQL Connectors, MySQL Router, Oracle Enterprise Manager for MySQL Database
- **Vulnerabilities:** Multiple CVEs as detailed in the CERT-FR bulletin.
- **Attack Vector:** Remote exploitation.
- **Exploitation Status:** Exploitation details are likely still being developed.
- **CVSS Score:** CVSS scores are not explicitly provided in the bulletin, but the severity is considered high due to the number of affected components and potential impact.
Impact
Successful exploitation of these vulnerabilities could lead to data breaches, service disruptions, and potential data corruption. The vulnerabilities could be used to conduct denial-of-service attacks, compromising the availability of MySQL services. The impact extends to organizations relying on MySQL for critical database operations.
What to do
- Refer to the Oracle security bulletin for the latest information and available patches: [https://www.oracle.com/security-alerts/cpujul2026](https://www.oracle.com/security-alerts/cpujul2026)
- Apply the recommended patches and updates promptly to mitigate the risks.
- Monitor security advisories and bulletins for further updates and guidance.
Why it matters
These vulnerabilities represent a significant security risk for organizations utilizing Oracle MySQL. Prompt patching and proactive security measures are crucial to protect against potential attacks and maintain data integrity and system availability. The wide range of affected products underscores the importance of a comprehensive security strategy that addresses vulnerabilities across the entire MySQL ecosystem.