Percona maintains a focused but strategically important database and backup product line that achieves prominence beyond its narrow scope due to the centrality of MySQL derivatives and operational tooling to enterprise infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the sensitivity of database platforms to authentication bypass, data exposure, and operational compromise. The exposure recurs across flagship products including Percona Server, XtraBackup, and XtraDB Cluster and clusters around information-disclosure weaknesses, command injection, privilege-escalation flaws, and synchronization issues that are endemic to database engines and their administrative interfaces. Defenders should prioritize Percona's security advisories and maintain close tracking of both database instances and backup tooling, as critical flaws in these components carry immediate blast radius to data confidentiality and availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Percona over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6662CRITICAL Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5. | Sep 20, 2016 | 9.8 | 78 | NO | YES |
CVE-2021-27928HIGH A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; an | Mar 19, 2021 | 7.2 | 56 | NO | YES |
CVE-2016-6663HIGH Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.1 | Dec 13, 2016 | 7.0 | 36 | NO | YES |
CVE-2016-6664HIGH mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5 | Dec 13, 2016 | 7.0 | 35 | NO | YES |
CVE-2026-25212CRITICAL An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add dat | Apr 2, 2026 | 9.9 | 34 | NO | NO |
CVE-2019-12301CRITICAL The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in | May 23, 2019 | 9.8 | 32 | NO | NO |
CVE-2020-15180CRITICAL A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker t | May 27, 2021 | 9.0 | 31 | NO | NO |
CVE-2020-26542CRITICAL An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Dire | Nov 9, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-34409CRITICAL In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path t | Jun 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-26701CRITICAL An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data expo | Mar 11, 2025 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Percona.
Media articles that mention a CVE ID that affects a product developed by Percona — matched by CVE ID, not by vendor name.