ThreatCluster

Multiple Vulnerabilities in MySQL Server Expose Systems to Denial of Service Attacks

First seen 18 Jun 2026, 19:24 UTC nvd.nist.gov 96% similarity 55

Article Content

Browse articles
ThreatCluster

On June 18, 2026, five critical vulnerabilities were disclosed in Oracle's MySQL Server, affecting versions 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. These vulnerabilities, identified as CVE-2026-34270, CVE-2026-34271, CVE-2026-34304, CVE-2026-22004, and CVE-2026-34272, allow low to high privileged attackers to exploit the server via network access. Successful exploitation can lead to a denial of service (DoS), causing the server to hang or crash repeatedly. The vulnerabilities are easily exploitable and have a CVSS score ranging from 4.9 to 6.5, indicating significant availability impacts. All vulnerabilities were published on April 21, 2026, and are currently unpatched, urging immediate attention from system administrators. The affected systems are primarily used in various enterprise environments, making them a potential target for attackers. Security professionals are advised to monitor for any signs of exploitation.

Key Points: • Five vulnerabilities in MySQL Server could lead to denial of service attacks. • Affected versions include 8.0.0-8.0.45, 8.4.0-8.4.8, and 9.0.0-9.6.0. • Exploitation can be performed by low to high privileged attackers with network access.

ThreatCluster AI How this analysis works

Timeline

2026-04-21
CVE-2026-34270 published
A vulnerability in MySQL Server allows low privileged attackers to cause a DoS.
nvd.nist.gov
2026-04-21
CVE-2026-34271 published
Another vulnerability in MySQL Server enables low privileged attackers to exploit the system.
nvd.nist.gov
2026-04-21
CVE-2026-34304 published
A high privileged attacker can exploit this vulnerability to crash MySQL Server.
nvd.nist.gov
2026-04-21
CVE-2026-22004 published
This vulnerability allows high privileged attackers to cause a DoS in MySQL Server.
nvd.nist.gov
2026-04-21
CVE-2026-34272 published
Low privileged attackers can exploit this vulnerability in MySQL Server's optimizer.
nvd.nist.gov
2026-06-18
Vulnerabilities disclosed
Multiple vulnerabilities in MySQL Server were disclosed, affecting enterprise systems.
nvd.nist.gov

Community

Browse all →

Tracked Entities in This Story