Junglewise Threat Intelligence

CVE-2026-87283: Oracle VM VirtualBox denial of service in Core

CVE-2026-87283 · Severity: medium · CVSS 6 · Published 2026-09-15

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single computer. A vulnerability in its Core component allows a high-privileged local attacker to trigger a complete denial of service (hang or crash) affecting the hypervisor and potentially the virtual machines running on it. The scope of impact extends beyond VirtualBox itself to other products hosted on the affected infrastructure.

Technical details

This is a denial-of-service vulnerability in Oracle VM VirtualBox Core component, triggered via an easily exploitable vector. The vulnerability requires high privilege access (PR:H) and local logon to the infrastructure (AV:L) where VirtualBox is running, with no user interaction needed (UI:N). A successful exploit causes a hang or repeated crash (complete DoS) of the VirtualBox process. The vulnerability has a scope change (S:C), meaning exploitation may impact connected products beyond VirtualBox. Patch availability for version 7.2.16 is not detailed in the advisory; users should consult Oracle's official security bulletins for mitigation guidance.

Affected products

  • Oracle VM VirtualBox 7.2.16

Timeline

  • 2026-09-15: disclosed

References

Related threats