CVE-2026-60747General(oracle / mysql_cluster)

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mysql_cluster
  • mysql_server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mysql_clustermysql_server

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity
    General

    CyStack has updated its analysis of CVE-2026-60747: a single packet drops a MySQL replica into a crash loop. A free-of-memory-not-on-the-heap bug (CWE-590) in MySQL replication's heartbeat decoder. Details from Phuc Nguyen (pucagit) https://cystack.net/research/cve-2026-60747-mysql #CyStack #MySQL #CVE https://t.co/padFlU1UZP

    Post summary

    The tweet references an updated analysis of CVE‑2026‑60747, providing technical vulnerability details but no PoC, exploit code, or remediation. It does not suggest active exploitation or a false positive.

    01030120
    3.7K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclemysql_cluster---
Apporaclemysql_cluster9.7.0--
Apporaclemysql_cluster9.7.1--
Apporaclemysql_server---
Apporaclemysql_server9.7.0--
Apporaclemysql_server9.7.1--

Explore more