The Oracle Critical Patch Update of July 2026 addresses 54 issues
in Oracle MySQL, 43 of which apply to the MySQL 9.7 series and to
the MySQL Router shipped with these ports. The 9.7 branch is
affected by every server issue of the 8.4 branch plus twelve
additional ones in code paths that only exist in 9.x.
The affected server components are Optimizer, Replication,
Group Replication (plugin and GCS), X Plugin, Clone Plugin,
InnoDB, JSON, JSON Duality, GIS, DDL, Configurator, Performance
Schema and Pluggable Authentication.
Most of the issues require an authenticated account, in many
cases one with high privileges, and let an attacker hang or
repeatedly crash the server, resulting in a denial of service.
Three issues need no credentials at all: CVE-2026-60315 (CVSS
8.2) is reachable over the X protocol and affects availability,
while CVE-2026-60314 and CVE-2026-60725 affect MySQL Router over
HTTP, the latter allowing unauthorized read and write access.
The highest rated issue for this branch is CVE-2026-60163 (CVSS
8.4) in the Group Replication plugin, exploitable locally with
full impact on confidentiality, integrity and availability.
CVE-2026-60181 in the Configurator component requires user
interaction and is specific to the 9.7 branch.
Please refer to the referenced CVE entries for the details of
each individual issue.