Denial of Service Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-87280

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87280?

An exploitable denial of service vulnerability exists in Oracle VM VirtualBox, affecting version 7.2.16. This vulnerability allows a high-privileged attacker who has access to the VirtualBox infrastructure to compromise the service. The attack requires human interaction, which makes it particularly concerning as it can lead to the unauthorized ability to induce a system hang or repeated crashes. This results in a complete denial of service for users relying on Oracle VM VirtualBox, potentially interrupting operations and impacting business continuity.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.