Core Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-60159

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60159?

A vulnerability exists in the Core component of the Oracle VM VirtualBox product, affecting version 7.2.12. It allows an attacker with high privileges and access to the infrastructure where Oracle VM VirtualBox runs to exploit this weakness. While the main impact is on Oracle VM VirtualBox, successful exploitation can have broader implications, potentially affecting other products in the environment. This vulnerability poses a significant security risk as it may lead to a complete takeover of Oracle VM VirtualBox, compromising the integrity and confidentiality of the hosted systems and services.

Affected Version(s)

Oracle VM VirtualBox 7.2.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.