MySQL on Linux: which version fixes what
MySQL publishes a large batch of CVEs every quarter, and most of them require an authenticated connection. That makes the raw count misleading and the exposure question the one worth asking.
SecAI tracks 477 distinct CVEs affecting MySQL across the 6 distributions below. Each row names the package version that fixes it on that release.
What it is, and why it is on your server
MySQL is Oracle's relational database, shipped by Ubuntu as mysql-8.0. Debian does not package it at all and ships MariaDB in its place, which is why the Debian columns on this page say so rather than showing zero.
Why its advisories behave the way they do
- Oracle ships CVEs in quarterly batches. A single critical patch update can name dozens at once, so a jump of forty in the count is a release schedule, not an event.
- Most require authentication, which means the real question is who can reach port 3306. A database bound to 0.0.0.0 turns an authenticated flaw into an internet-facing one.
- The client library has its own advisories. Applications link libmysqlclient, and patching the server does not patch them.
Check what you are actually running
The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.
dpkg-query -W -f='${Package} ${Version}\n' mysql-server mysql-client 2>/dev/nullrpm -q mysql-server mysqlCheck what it is listening on with `ss -lntp | grep 3306`. Bound to 127.0.0.1 is a very different server from bound to 0.0.0.0.
Fixed versions, per distribution
Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.
Ubuntu 22.04 LTSsource package: mysql-8.0
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-46936 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-47012 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-47023 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-47052 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-47064 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60145 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60163 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60177 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60178 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60182 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60183 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60184 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60185 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60186 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60187 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60188 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60189 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60190 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60191 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60315 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60316 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60331 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60332 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60585 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
| CVE-2026-60747 | 2026-08-31 | 8.0.46-0ubuntu0.22.04.4 |
Showing the 25 most recent of 462 that apply to Ubuntu 22.04 LTS.
Ubuntu 24.04 LTSsource package: mysql-8.0
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-46936 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-47012 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-47023 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-47052 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-47064 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60145 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60163 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60177 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60178 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60182 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60183 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60184 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60185 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60186 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60187 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60188 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60189 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60190 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60191 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60315 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60316 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60331 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60332 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60585 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
| CVE-2026-60747 | 2026-08-31 | 8.0.46-0ubuntu0.24.04.4 |
Showing the 25 most recent of 224 that apply to Ubuntu 24.04 LTS.
Debian 12 (bookworm)
Debian ships MariaDB in place of MySQL. There is nothing to patch here, which is not the same as being up to date with it.
Debian 13 (trixie)
Debian ships MariaDB in place of MySQL. There is nothing to patch here, which is not the same as being up to date with it.
Rocky Linux 9source package: mysql
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-21998 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22001 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22002 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22004 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22005 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22009 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22015 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-22017 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34267 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34270 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34271 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34276 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34278 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34293 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34303 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34304 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-34308 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-35236 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-35237 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-35238 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-35239 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-35240 | 2026-06-11 | 0:8.0.46-1.el9_8.rocky.0.1 |
| CVE-2026-21936 | 2026-03-18 | 0:8.0.45-1.el9_7 |
| CVE-2026-21937 | 2026-03-18 | 0:8.0.45-1.el9_7 |
| CVE-2026-21941 | 2026-03-18 | 0:8.0.45-1.el9_7 |
Showing the 25 most recent of 189 that apply to Rocky Linux 9.
AlmaLinux 9source package: mysql
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-46936 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-47012 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-47023 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-47052 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-47064 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60145 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60163 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60177 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60178 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60182 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60183 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60184 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60185 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60186 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60187 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60188 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60189 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60190 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60191 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60315 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60316 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60331 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60332 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60585 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
| CVE-2026-60747 | 2026-08-19 | 8.4.11-1.module_el9.8.0+295+1681b9df |
Showing the 25 most recent of 324 that apply to AlmaLinux 9.
Advisory data last refreshed 26 September 2026. It is re-read daily.
What this page does not tell you
It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.
It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.
Read next
Find out which of these you are running
One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, MySQL included. It changes nothing.