Red Hat released RHSA-2026:56936 for the mysql:8.4 module in Red Hat Enterprise Linux 8, delivering MySQL 8.4.11 and rating the update Important. The advisory addresses numerous vulnerabilities across MySQL components including Replication, Optimizer, Clone Plugin, Group Replication, X Plugin, InnoDB, JSON, DDL, Performance Schema, and Pluggable Auth, with affected builds spanning multiple RHEL 8 architectures and Extended Life Cycle 8.10 variants.
A corresponding AlmaLinux 8 advisory, tracked by a Nessus plugin as ALSA-2026:56936, mirrors the MySQL fixes across a broad set of repositories and packages. The referenced flaws include weakness classes such as uncaught exceptions (CWE-248), which can cause crashes or unintended behavior, and incorrect privilege assignment (CWE-266), which can enable unauthorized access or privilege escalation; Tenable said no known exploits were available at publication and pointed to CVEs including CVE-2026-60315 and CVE-2026-60163 for scoring details.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A Tenable Nessus plugin published on 2026-08-20 documents AlmaLinux 8 advisory ALSA-2026:56936, referencing the same MySQL CVE set and noting the advisory patch publication date of 2026-08-19 with no known exploits available.
Red Hat issued Important advisory RHSA-2026:56936 for RHEL 8 on 2026-08-19, rebasing the mysql:8.4 module to MySQL 8.4.11 and fixing numerous vulnerabilities across components such as Replication, Optimizer, Clone Plugin, Group Replication, X Plugin, InnoDB, JSON, DDL, Performance Schema, and Pluggable Auth.
The Nessus plugin states that the vulnerabilities addressed by the AlmaLinux advisory, including numerous MySQL CVEs later referenced by Red Hat, were published on 2026-07-21.
MITRE published the CWE-248 entry defining Uncaught Exception as a base-level weakness in which thrown exceptions are not caught, potentially causing crashes, denial of service, or exposure of sensitive data.
MITRE published the CWE-266 entry describing Incorrect Privilege Assignment as a base-level weakness that can enable unintended access, privilege gain, or identity assumption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.