Junglewise Threat Intelligence

CVE-2026-87277: Oracle VM VirtualBox denial of service via RDP

CVE-2026-87277 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that allows users to run multiple operating systems on a single computer. An unauthenticated attacker with network access can exploit a vulnerability in the RDP component to crash the VirtualBox application, disrupting virtual machine operations and causing complete service outage to users relying on virtualized environments.

Technical details

This is a denial-of-service vulnerability in Oracle VM VirtualBox 7.2.16's RDP (Remote Desktop Protocol) handling component. The vulnerability is easily exploitable and requires only network access; no authentication or user interaction is needed. An unauthenticated attacker can send specially crafted RDP traffic to cause the VirtualBox process to hang or crash repeatedly, resulting in complete unavailability of virtualized systems. The vulnerability has been rated high severity with a CVSS 3.1 score of 7.5 affecting availability.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats