Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Percona

First CVE: Dec 13, 2013Active for: 13 yearsTotal CVEs: 22
55.3
VTI Score
TOP TARGET

Percona maintains a focused but strategically important database and backup product line that achieves prominence beyond its narrow scope due to the centrality of MySQL derivatives and operational tooling to enterprise infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of database platforms to authentication bypass, data exposure, and operational compromise. The exposure recurs across flagship products including Percona Server, XtraBackup, and XtraDB Cluster and clusters around information-disclosure weaknesses, command injection, privilege-escalation flaws, and synchronization issues that are endemic to database engines and their administrative interfaces. Defenders should prioritize Percona's security advisories and maintain close tracking of both database instances and backup tooling, as critical flaws in these components carry immediate blast radius to data confidentiality and availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Percona over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2013
12 years ago
Most Recent CVE
Apr 2, 2026
114 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-6662CRITICAL
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.
Sep 20, 20169.878NOYES
CVE-2021-27928HIGH
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; an
Mar 19, 20217.256NOYES
CVE-2016-6663HIGH
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.1
Dec 13, 20167.036NOYES
CVE-2016-6664HIGH
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5
Dec 13, 20167.035NOYES
CVE-2026-25212CRITICAL
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add dat
Apr 2, 20269.934NONO
CVE-2019-12301CRITICAL
The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in
May 23, 20199.832NONO
CVE-2020-15180CRITICAL
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker t
May 27, 20219.031NONO
CVE-2020-26542CRITICAL
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Dire
Nov 9, 20209.831NONO
CVE-2023-34409CRITICAL
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path t
Jun 6, 20239.830NONO
CVE-2025-26701CRITICAL
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data expo
Mar 11, 202510.029NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
18%
45%
32%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (13.6%)
Network18 (81.8%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (63.6%)
High7 (31.8%)
Unknown1 (4.5%)
User Interaction
None21 (95.5%)
Unknown1 (4.5%)
Required0 (0.0%)
Privileges Required
Low7 (31.8%)
High1 (4.5%)
None13 (59.1%)
Unknown1 (4.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
18.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Percona.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Percona — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Percona's Products

View all 4 CNAs →

Top CWEs