Core Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-87282

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87282?

An easily exploitable vulnerability exists in the Oracle VM VirtualBox product, specifically within the core component. This flaw allows a high-privileged attacker, who has access to the infrastructure where Oracle VM VirtualBox operates, to compromise the application. The impact of successful exploitation can lead to unauthorized actions, including the potential for inducing hangs or crashes, resulting in a complete denial of service of the affected VirtualBox instance. While primarily pertaining to Oracle VM VirtualBox, attackers may leverage this vulnerability to affect other interconnected products due to its scope. The supported version affected by this issue is 7.2.16.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.