Oracle VM VirtualBox Vulnerability in Windows Environment
CVE-2026-87270

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87270?

A critical security flaw exists in Oracle VM VirtualBox, specifically within its Core component, impacting the 7.2.16 version on Windows hosts. This vulnerability enables a low privileged attacker, who has access to the infrastructure running Oracle VM VirtualBox, to exploit the system with relative ease. If successfully executed, such an attack can lead to full control of the Oracle VM VirtualBox environment, posing significant risks to data confidentiality, integrity, and availability. Organizations using Oracle VM VirtualBox are encouraged to assess their security protocols and apply necessary mitigations.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.