Junglewise Threat Intelligence

CVE-2026-71113: Oracle VM VirtualBox denial of service via RDP

CVE-2026-71113 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows organizations to run multiple operating systems on a single physical computer. An attacker with network access can trigger a crash or hang that prevents the virtualization platform from operating, causing downtime to virtual machines and impacting business operations. This vulnerability can be exploited without authentication or user interaction.

Technical details

A network-reachable denial-of-service vulnerability exists in the core component of Oracle VM VirtualBox version 7.2.14. The vulnerability can be exploited via the RDP (Remote Desktop Protocol) interface without authentication or special privileges. An attacker can send specially crafted network packets to cause the virtualization service to hang or crash repeatedly, resulting in complete unavailability. The attack has low complexity and does not require user interaction; however, it only impacts service availability and does not lead to data confidentiality or integrity breaches.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats