Executive brief
Oracle VM VirtualBox is a virtualization platform used to run virtual machines on corporate infrastructure. A vulnerability in the core component allows a privileged attacker with local access to cause the application to hang or crash repeatedly, disrupting operations of all virtual machines running on the affected host.
Technical details
A denial of service vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.16. The vulnerability is easily exploitable and requires high privileges (administrative/root access) and user interaction from a different user than the attacker. The attack vector is local, targeting the infrastructure where VirtualBox is running. Successful exploitation results in a hang or repeated crash of the VirtualBox process, causing complete unavailability of all virtual machines hosted on that system. Patch availability has not been confirmed in the advisory.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed
- other: CVE-2026-87280 assigned