The Oracle Critical Patch Update of July 2026 addresses 54 issues
in Oracle MySQL, 31 of which apply to the MySQL 8.4 series and to
the MySQL Router shipped with these ports.
The affected server components are Optimizer, Replication,
Group Replication (plugin and GCS), X Plugin, Clone Plugin,
InnoDB, JSON, DDL, Performance Schema and Pluggable
Authentication.
Most of the issues require an authenticated account, in many
cases one with high privileges, and let an attacker hang or
repeatedly crash the server, resulting in a denial of service.
Three issues need no credentials at all: CVE-2026-60315 (CVSS
8.2) is reachable over the X protocol and affects availability,
while CVE-2026-60314 and CVE-2026-60725 affect MySQL Router over
HTTP, the latter allowing unauthorized read and write access.
The highest rated issue for this branch is CVE-2026-60163 (CVSS
8.4) in the Group Replication plugin, exploitable locally with
full impact on confidentiality, integrity and availability.
Please refer to the referenced CVE entries for the details of
each individual issue.