Technology · Oracle
Oracle VirtualBox vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 70 vulnerabilities in Oracle VirtualBox: 0 in the last 7 days and 55 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-87285, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 55
- Critical, all time
- 1
- Exploited in the wild
- 1
About Oracle VirtualBox
VirtualBox is an open-source hosted hypervisor for x86 virtualization.
Latest Oracle VirtualBox vulnerabilities
- CVE-2026-87285: Oracle VM VirtualBox denial of service in CoremediumCVSS 6EPSS 0.2%
- CVE-2026-87284: Oracle VM VirtualBox denial of service in CorelowCVSS 3.2EPSS 0.1%
- CVE-2026-87283: Oracle VM VirtualBox denial of service in CoremediumCVSS 6EPSS 0.2%
- CVE-2026-87282: Oracle VM VirtualBox denial of service in CoremediumCVSS 6EPSS 0.2%
- CVE-2026-87281: Oracle VM VirtualBox information disclosure in CorelowCVSS 3.2EPSS 0.2%
- CVE-2026-87280: Oracle VM VirtualBox denial of service in CoremediumCVSS 4.2EPSS 0.1%
- CVE-2026-87279: Oracle VM VirtualBox denial of service in Core componentmediumCVSS 6.1EPSS 0.1%
- CVE-2026-87278: Oracle VM VirtualBox denial of service and data modification in CoremediumCVSS 6.1EPSS 0.1%
- CVE-2026-87277: Oracle VM VirtualBox denial of service via RDPhighCVSS 7.5EPSS 0.5%
- CVE-2026-87276: Oracle VirtualBox privilege escalation in CorehighCVSS 7.5EPSS 0.1%
- CVE-2026-87275: Oracle VM VirtualBox information disclosure and denial of service in CoremediumCVSS 4.6EPSS 0.2%
- CVE-2026-87274: Oracle VM VirtualBox denial of service in CoremediumCVSS 4.4EPSS 0.1%
- CVE-2026-87273: Oracle VM VirtualBox privilege escalation in CorehighCVSS 8.6EPSS 0.2%
- CVE-2026-87271: Oracle VM VirtualBox privilege escalation in CorehighCVSS 7.8EPSS 0.2%
- CVE-2026-87270: Oracle VM VirtualBox privilege escalation in CorehighCVSS 7.8EPSS 0.2%
- CVE-2026-87269: Oracle VM VirtualBox privilege escalation in Core on WindowshighCVSS 7.8EPSS 0.2%
- CVE-2026-87268: Oracle VM VirtualBox privilege escalation in CorehighCVSS 7.8EPSS 0.2%
- CVE-2026-87267: Oracle VM VirtualBox denial of service via RDPmediumCVSS 5.3EPSS 0.3%
- CVE-2026-71151: Oracle VM VirtualBox privilege escalation via Core componentmediumCVSS 5.6EPSS 0.1%
- CVE-2026-71141: Oracle VM VirtualBox local privilege escalation in Core componenthighCVSS 7.7EPSS 0.2%
- CVE-2026-71140: Oracle VM VirtualBox data access vulnerability in CorelowCVSS 3.4EPSS 0.2%
- CVE-2026-71139: Oracle VM VirtualBox denial of service in CoremediumCVSS 4.4EPSS 0.2%
- CVE-2026-71138: Oracle VM VirtualBox denial of service and data access in Core componenthighCVSS 7.3EPSS 0.2%
- CVE-2026-71137: Oracle VM VirtualBox denial of service in CoremediumCVSS 6EPSS 0.2%
- CVE-2026-71136: Oracle VM VirtualBox privilege escalation in Core componenthighCVSS 7.3EPSS 0.2%
Most severe Oracle VirtualBox vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2008-3431: Oracle VirtualBox Insufficient Input Validation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-87273: Oracle VM VirtualBox privilege escalation in CorehighCVSS 8.6EPSS 0.2%
- CVE-2026-71131: Oracle VM VirtualBox privilege escalation in CorehighCVSS 8.6EPSS 0.2%
- CVE-2017-3332: Oracle VM VirtualBox integrity and availability breach in SVGA EmulationhighCVSS 8.4
- CVE-2017-3316: Oracle VM VirtualBox privilege escalation in GUI update downloaderhighCVSS 8.4
- CVE-2026-71130: Oracle VM VirtualBox RDP remote access vulnerability in CorehighCVSS 8.2EPSS 0.4%
- CVE-2026-71129: Oracle VM VirtualBox privilege escalation in CorehighCVSS 8.2EPSS 0.2%
- CVE-2017-3290: Oracle VM VirtualBox integrity and DoS vulnerability in Shared FolderhighCVSS 7.9
- CVE-2026-87271: Oracle VM VirtualBox privilege escalation in CorehighCVSS 7.8EPSS 0.2%
- CVE-2026-87270: Oracle VM VirtualBox privilege escalation in CorehighCVSS 7.8EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 16 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 21 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 18 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/virtualbox.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle VirtualBox vulnerabilities", https://junglewise.ai/threats/technologies/virtualbox, 26 September 2026.