Skip to content
OracleCVE-2026-87274

Oracle VM VirtualBox: denial of service via Core

Medium4.4CVE-2026-87274 · Published Sep 15, 2026 · updated Sep 23, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).

Oracle advisory

Affected versions

PackageAffectedFixed in
Oracle VM VirtualBox
Product
<= 7.2.16No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Oracle advisories

All Oracle
Advisory
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle GraalVM for JDK: data tampering via Compiler
High7.0Sep 15
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle VM VirtualBox: flaw in Core
Low3.2Sep 15
Oracle VM VirtualBox: denial of service via Core
Medium6.0Sep 15
Oracle GraalVM: takeover via Compiler
High8.1Sep 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.