Denial of Service Vulnerability in Oracle VM VirtualBox by Oracle
CVE-2026-87285

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87285?

A vulnerability in Oracle VM VirtualBox allows a high privileged attacker with access to the infrastructure where the software runs to exploit the system. The issue, present in version 7.2.16, can lead to a denial of service, causing the application to hang or crash repeatedly. As a result, users and systems relying on Oracle VM VirtualBox may experience significant disruptions. Organizations should take immediate steps to apply the necessary patches to prevent exploitation of this vulnerability.

Affected Version(s)

Oracle VM VirtualBox 7.2.16

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.