MySQL logo

MySQL Community Edition Security Advisory

Back to MySQL Community Security Advisories

MySQL Community Edition Security Advisory: August 2026

This page provides a view of the vulnerabilities addressed in MySQL Community Edition in the August 2026 Oracle MySQL Critical Security Patch Update. For this page, “MySQL Community Edition” means Community-distributed MySQL products. Only rows that map to Community-distributed components are included here. For the complete risk matrix, refer to Oracle’s August 2026 MySQL appendix.

Scope

The broader MySQL Community Edition product set includes MySQL Server, MySQL Cluster, MySQL Shell, MySQL Router, MySQL NDB Cluster, MySQL Workbench, and MySQL Connectors. Based on the affected rows shown in the August 2026 Oracle MySQL Risk Matrix, the MySQL Community Edition products represented on this page are:

MySQL ClusterMySQL ShellMySQL Connectors

How to use this page

Summary

MySQL Community Edition rows8
Affected product families3
Remote exploitable without auth4
Highest CVSS base score8.2

Counts above reflect only the MySQL Community Edition rows represented on this page from the August 2026 Oracle MySQL Risk Matrix.

Affected MySQL Community Edition products and vulnerable version ranges

MySQL Community Edition vulnerability details

CVE IDProductComponentProtocolRemote Exploit without Auth.?Base ScoreAttack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentialityIntegrityAvailabilitySupported Versions Affected
CVE-2026-60592MySQL ClusterCluster: NDB OperatorMySQL ProtocolYes8.2NetworkLowNoneNoneUnchangedNoneLowHigh8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
CVE-2025-14821MySQL ClusterCluster: General (libssh)NoneNo7.8LocalLowLowNoneUnchangedHighHighHigh8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
CVE-2026-70724MySQL ClusterCluster: GeneralHTTPYes7.5NetworkHighNoneRequiredUnchangedHighHighHigh8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2
CVE-2025-13151MySQL ClusterCluster: General (Libtasn1)HTTPYes7.5NetworkLowNoneNoneUnchangedNoneNoneHigh8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1
CVE-2026-71084MySQL ConnectorsConnector/ODBCNoneNo6.8LocalLowNoneNoneUnchangedLowNoneHigh26.7.0
CVE-2026-71079MySQL ConnectorsConnector/ODBCMySQL ProtocolNo6.5NetworkLowLowNoneUnchangedNoneNoneHigh26.7.0
CVE-2026-0968MySQL ShellShell: Core Client (libssh)MySQL ProtocolYes5.9NetworkHighNoneNoneUnchangedNoneHighNone26.7.0
CVE-2026-71073MySQL ConnectorsConnector/ODBCNoneNo5.5LocalLowNoneRequiredUnchangedNoneNoneHigh26.7.0

Additional CVEs addressed are:

The patch for CVE-2026-0968 also addresses CVE-2025-14821, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, and CVE-2026-0967.

The patch for CVE-2025-14821 also addresses CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, and CVE-2026-0968.