Vulnerability in Oracle VM VirtualBox for Windows by Oracle
CVE-2026-87271

7.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87271?

A vulnerability exists in Oracle VM VirtualBox 7.2.16 that allows a low privileged attacker with access to the infrastructure where the software runs to compromise the application. This issue primarily affects Windows hosts and could lead to unauthorized control over the Oracle VM VirtualBox environment. Attackers could exploit this vulnerability to impact the confidentiality, integrity, and availability of the virtualized application.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.