Scope
The broader MySQL Community Edition product set includes MySQL Server, MySQL Cluster, MySQL Shell, MySQL Router, MySQL NDB Cluster, MySQL Workbench, and MySQL Connectors. Based on the affected rows shown in the August 2026 Oracle MySQL Risk Matrix, the MySQL Community Edition products represented on this page are:
How to use this page
- Use the Product column to confirm that the row applies to a Community-distributed component.
- Use Supported Versions Affected as the vulnerable version range, not the fixed version.
- Use the CVE, component, protocol, exploitability, and CVSS columns to determine exposure and severity.
- Use the corresponding MySQL Community release documentation to identify the release that contains the fix.
Summary
Counts above reflect only the MySQL Community Edition rows represented on this page from the August 2026 Oracle MySQL Risk Matrix.
Affected MySQL Community Edition products and vulnerable version ranges
- MySQL Cluster: 8.0.0-8.0.47, 8.0.0-8.0.48, 8.4.0-8.4.10, 8.4.0-8.4.11, 9.7.0-9.7.1, 9.7.0-9.7.2
- MySQL Shell: 26.7.0
- MySQL Connectors: 26.7.0
MySQL Community Edition vulnerability details
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? | Base Score | Attack Vector | Attack Complexity | Privileges Required | User Interaction | Scope | Confidentiality | Integrity | Availability | Supported Versions Affected |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-60592 | MySQL Cluster | Cluster: NDB Operator | MySQL Protocol | Yes | 8.2 | Network | Low | None | None | Unchanged | None | Low | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 |
| CVE-2025-14821 | MySQL Cluster | Cluster: General (libssh) | None | No | 7.8 | Local | Low | Low | None | Unchanged | High | High | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 |
| CVE-2026-70724 | MySQL Cluster | Cluster: General | HTTP | Yes | 7.5 | Network | High | None | Required | Unchanged | High | High | High | 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2 |
| CVE-2025-13151 | MySQL Cluster | Cluster: General (Libtasn1) | HTTP | Yes | 7.5 | Network | Low | None | None | Unchanged | None | None | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 |
| CVE-2026-71084 | MySQL Connectors | Connector/ODBC | None | No | 6.8 | Local | Low | None | None | Unchanged | Low | None | High | 26.7.0 |
| CVE-2026-71079 | MySQL Connectors | Connector/ODBC | MySQL Protocol | No | 6.5 | Network | Low | Low | None | Unchanged | None | None | High | 26.7.0 |
| CVE-2026-0968 | MySQL Shell | Shell: Core Client (libssh) | MySQL Protocol | Yes | 5.9 | Network | High | None | None | Unchanged | None | High | None | 26.7.0 |
| CVE-2026-71073 | MySQL Connectors | Connector/ODBC | None | No | 5.5 | Local | Low | None | Required | Unchanged | None | None | High | 26.7.0 |
Additional CVEs addressed are:
The patch for CVE-2026-0968 also addresses CVE-2025-14821, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, and CVE-2026-0967.
The patch for CVE-2025-14821 also addresses CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, and CVE-2026-0968.