CVE-2026-46862
published 2026-06-16CVE-2026-46862: Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
37.3th percentile
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle_corporation | mysql_router | 8.4.0 – 8.4.9 | — |
| oracle_corporation | mysql_router | 9.0.0 – 9.7.0 | — |
| ubuntu | mysql-8.0 | — | — |
| ubuntu | mysql-8.4 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2026-06-24
CVE-2026-46862 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
USN-8457-1 fixed several vulnerabilities in MySQL. This update
provides the corresponding fixes for MySQL on Ubuntu 20.04 LTS
Original advisory details:
It was discovered that MySQL Router incorrectly handled repeated TLS
protocol upgrade requests. An unauthenticated remote attacker could
possibly use this issue to cause MySQL Router to crash, resulting in a
denial of service. (CVE-2026-46862)
It was discovered that MySQL Server incorrectly handled connection
authentication. An unauthenticated remote attacker could possibly use this
issue to cause MySQL to crash, resulting in a denial of service.
(CVE-2026-46863)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2026-06-22
CVE-2026-46863 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
It was discovered that MySQL Router incorrectly handled repeated TLS
protocol upgrade requests. An unauthenticated remote attacker could
possibly use this issue to cause MySQL Router to crash, resulting in a
denial of service. (CVE-2026-46862)
It was discovered that MySQL Server incorrectly handled connection
authentication. An unauthenticated remote attacker could possibly use this
issue to cause MySQL to crash, resulting in a denial of service.
(CVE-2026-46863)
Instructions: This update may use a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
GHSA
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).
ghsa_unreviewed·2026-06-17
CVE-2026-46862 [HIGH] CWE-400 Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General).
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVEList
CVE-2026-46862: Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General)
cvelistv5·2026-06-16·CVSS 7.5
CVE-2026-46862 [HIGH] CVE-2026-46862: Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General)
Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published