Vulnerability in Oracle VM VirtualBox 7.2.14 by Oracle
CVE-2026-71128

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71128?

This vulnerability in Oracle VM VirtualBox enables a high-privileged attacker with access to the host infrastructure to compromise the VirtualBox environment. While the vulnerability is restricted to the Oracle VM VirtualBox product, it can result in significant repercussions for other associated systems. Attackers exploiting this vulnerability can cause the Oracle VM VirtualBox to hang or crash repeatedly, leading to a denial of service situation. Users should stay informed about available patches and updates recommended by Oracle to safeguard their environments.

Affected Version(s)

Oracle VM VirtualBox 7.2.14

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.