Documented CVEs
10 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Oracle MySQL Server & Ecosystem |
| Vendor / Project | oracle |
| Canonical ID | oracle:mysql |
| Versioning Scheme | semver |
| CPE Identifiers | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:mysql_router:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:mysql_shell:*:*:*:*:*:*:*:*cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Overall Posture | CRITICAL |
| Recommended Safe Release | NDB Operator 8.0.47 |
Documented CVEs
10 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
0 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
10 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to NDB Operator 8.0.47 to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
0.5 %
= Stable over 30d
0
No active KEV
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2026-46850 | 9.9 (CRITICAL) | 0.5% | No | < v2026.2.1+9.6.2 | 2026.2.1+9.6.2 | Analysis β |
| CVE-2026-46860 | 9.8 (CRITICAL) | 0.5% | No | < v9.7.1 | 9.7.1, 8.4.10 LTS | Analysis β |
| CVE-2026-46861 | 9.6 (CRITICAL) | 0.4% | No | < v8.0.47 | 8.0.47, 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-46870 | 8.5 (HIGH) | 0.3% | No | < v2026.2.1+9.6.2 | 2026.2.1+9.6.2 | Analysis β |
| CVE-2026-60163 | 8.4 (HIGH) | 0.3% | No | < v8.0.47 | 8.0.47, 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-60592 | 8.2 (HIGH) | 0.4% | No | < vNDB Operator 8.0.47 | NDB Operator 8.0.47, 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-46862 | 7.5 (HIGH) | 0.5% | No | < v8.4.10 | 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-60316 | 7.2 (HIGH) | 0.4% | No | < v8.0.47 | 8.0.47, 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-61094 | 7.2 (HIGH) | 0.5% | No | < v8.0.47 | 8.0.47, 8.4.10, 9.7.1 | Analysis β |
| CVE-2026-60623 | 7.1 (HIGH) | 0.2% | No | < v9.7.2 | 9.7.2, 8.4.10 | Analysis β |
Are you operating Oracle MySQL Server & Ecosystem in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: