MySQL Zero-Day Allows Database Takeover. From Softpedia.
Polish security researcher Dawid Golunski has discovered two zero-days, CVE-2016-6662 and CVE-2016-6663, that affect all currently supported MySQL versions and allow an attacker to take full control over the database.
Golunski says he informed Oracle of both issues, along with other database vendors that forked the MySQL engine in the past such as MariaDB and PerconaDB.
Today the researcher took the extreme measure of publishing proof-of-concept exploit code for CVE-2016-6662 after both MariaDB and PerconaDB fixed the vulnerabilities and Oracle did not