Junglewise Threat Intelligence

CVE-2026-87274: Oracle VM VirtualBox denial of service in Core

CVE-2026-87274 · Severity: medium · CVSS 4.4 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that runs virtual machines on enterprise infrastructure. This vulnerability allows a low-privileged user with local access to crash or hang VirtualBox, disrupting hosted virtual machines. The attack requires user interaction and is difficult to exploit, but a successful attack results in complete service unavailability.

Technical details

This is a difficult-to-exploit denial-of-service vulnerability in the Core component of Oracle VM VirtualBox 7.2.16. The vulnerability requires a low-privileged attacker with local logon access to the infrastructure running VirtualBox, and successful exploitation requires human interaction from another user. An attacker can cause the VirtualBox process to hang or crash repeatedly, resulting in complete denial of service with no compromise of confidentiality or integrity. The attack vector is local (LV:L) with high complexity (AC:H) and requires user interaction (UI:R).

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats