FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

MySQL 9.7 -- Multiple vulnerabilities

Affected packages
mysql97-client < 9.7.2
mysql97-server < 9.7.2

Details

VuXML ID 10f5f76e-90a5-11f1-bc30-3497f65b111b
Discovery 2026-07-21
Entry 2026-08-05

The Oracle Critical Patch Update of July 2026 addresses 54 issues in Oracle MySQL, 43 of which apply to the MySQL 9.7 series and to the MySQL Router shipped with these ports. The 9.7 branch is affected by every server issue of the 8.4 branch plus twelve additional ones in code paths that only exist in 9.x.

The affected server components are Optimizer, Replication, Group Replication (plugin and GCS), X Plugin, Clone Plugin, InnoDB, JSON, JSON Duality, GIS, DDL, Configurator, Performance Schema and Pluggable Authentication.

Most of the issues require an authenticated account, in many cases one with high privileges, and let an attacker hang or repeatedly crash the server, resulting in a denial of service. Three issues need no credentials at all: CVE-2026-60315 (CVSS 8.2) is reachable over the X protocol and affects availability, while CVE-2026-60314 and CVE-2026-60725 affect MySQL Router over HTTP, the latter allowing unauthorized read and write access. The highest rated issue for this branch is CVE-2026-60163 (CVSS 8.4) in the Group Replication plugin, exploitable locally with full impact on confidentiality, integrity and availability. CVE-2026-60181 in the Configurator component requires user interaction and is specific to the 9.7 branch.

Please refer to the referenced CVE entries for the details of each individual issue.

References

CVE Name CVE-2026-46936
CVE Name CVE-2026-47008
CVE Name CVE-2026-47012
CVE Name CVE-2026-47023
CVE Name CVE-2026-47052
CVE Name CVE-2026-47064
CVE Name CVE-2026-60145
CVE Name CVE-2026-60163
CVE Name CVE-2026-60174
CVE Name CVE-2026-60177
CVE Name CVE-2026-60178
CVE Name CVE-2026-60181
CVE Name CVE-2026-60182
CVE Name CVE-2026-60183
CVE Name CVE-2026-60184
CVE Name CVE-2026-60185
CVE Name CVE-2026-60186
CVE Name CVE-2026-60187
CVE Name CVE-2026-60188
CVE Name CVE-2026-60189
CVE Name CVE-2026-60190
CVE Name CVE-2026-60191
CVE Name CVE-2026-60194
CVE Name CVE-2026-60195
CVE Name CVE-2026-60311
CVE Name CVE-2026-60314
CVE Name CVE-2026-60315
CVE Name CVE-2026-60316
CVE Name CVE-2026-60324
CVE Name CVE-2026-60331
CVE Name CVE-2026-60332
CVE Name CVE-2026-60585
CVE Name CVE-2026-60718
CVE Name CVE-2026-60725
CVE Name CVE-2026-60747
CVE Name CVE-2026-61081
CVE Name CVE-2026-61093
CVE Name CVE-2026-61094
CVE Name CVE-2026-61096
CVE Name CVE-2026-61108
CVE Name CVE-2026-61109
CVE Name CVE-2026-61128
CVE Name CVE-2026-61144
URL https://dev.mysql.com/community/security/advisories/2026-07-21/
URL https://www.oracle.com/security-alerts/cpujul2026.html