Junglewise Threat Intelligence

CVE-2026-87267: Oracle VM VirtualBox denial of service via RDP

CVE-2026-87267 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows organizations to run multiple operating systems on a single physical server. A low-privileged attacker with network access can exploit a flaw in the Core component to cause the hypervisor to hang or crash repeatedly, disrupting all virtual machines running on the affected host and resulting in complete service outages.

Technical details

A difficult-to-exploit denial-of-service vulnerability exists in Oracle VM VirtualBox 7.2.16's Core component, reachable via the RDP (Remote Desktop Protocol) network interface. A low-privileged attacker with network access can trigger the vulnerability without user interaction to cause the hypervisor to hang or crash repeatedly, resulting in complete unavailability of the system. The vulnerability impacts only availability; no data confidentiality or integrity compromise is possible. A patch is presumed available from Oracle, though the advisory references do not display functional patch information.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats