Junglewise Threat Intelligence

CVE-2026-87282: Oracle VM VirtualBox denial of service in Core

CVE-2026-87282 · Severity: medium · CVSS 6 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows organizations to run multiple virtual machines on a single physical server. A vulnerability in the Core component allows a high-privileged attacker with local access to trigger a denial-of-service condition, causing the virtualization system to hang or crash repeatedly. This disrupts all virtual machines running on the affected host, potentially impacting business operations.

Technical details

This is a denial-of-service vulnerability in the Core component of Oracle VM VirtualBox version 7.2.16. The vulnerability requires high privilege level (PR:H) and local access (AV:L) to the host system running VirtualBox, with no user interaction needed. A successful exploit results in a hang or complete crash of the virtualization system, causing unavailability of all hosted virtual machines. The scope is marked as changed (S:C), indicating that the impact extends beyond the VirtualBox application itself to other products or systems depending on it. Patch availability and specific technical remediation details are not disclosed in the available advisory information.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats