Vulnerability in Oracle VM VirtualBox by Oracle Affecting Core Components
CVE-2026-87284

3.2LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87284?

A vulnerability exists in Oracle VM VirtualBox, specifically within its core component, enabling an attacker with high privileges to compromise the system if they have access to the infrastructure. This vulnerability primarily affects version 7.2.16, and while it is contained within Oracle VM VirtualBox, successful exploitation may have broader implications for other products. Attackers can leverage this flaw to execute a partial denial of service, impacting the availability of the virtualization environment. It is crucial for organizations using this software to assess their security posture and take appropriate measures to mitigate potential risks.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.