Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A vulnerability in the core component of Oracle VM VirtualBox enables an unauthenticated attacker who can reach the host via Remote Desktop Protocol to force the guest management interface to hang or repeatedly crash, resulting in an availability interruption. The flaw is a classic resource‑exhaustion weakness (CWE‑400) that can be triggered without user interaction and does not affect confidentiality or integrity.

Affected Systems

Oracle Corporation’s VirtualBox Virtualization product, version 7.2.16, is the only version identified as affected. No other releases are listed in the advisory, so systems running earlier or later releases are not known to be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity availability impact. The EPSS figure of less than 1% suggests that, while exploitation is possible, it is not frequently observed. The vulnerability is not currently listed in the CISA KEV catalog, meaning no confirmed widespread exploit activity has been reported. The likely attack path involves an unauthenticated RDP connection to the VirtualBox host; the attacker does not need special privileges or authentication, making the exploitation straightforward once the host is reachable over the network.

Generated by OpenCVE AI on September 16, 2026 at 16:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security update that patches the VirtualBox core component, or upgrade to the latest supported release.
  • Close or restrict inbound RDP traffic (port 3389) to VirtualBox hosts, limiting exposure to only trusted networks or hosts.
  • Implement network segmentation or firewall rules to isolate VirtualBox management interfaces from the public or untrusted segments.

Generated by OpenCVE AI on September 16, 2026 at 16:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Remote RDP Denial of Service in Oracle VM VirtualBox 7.2.16

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:51.906Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87277

cve-icon Vulnrichment

Updated: 2026-09-15T23:12:26.367Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T20:19:16.460

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-87277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:15:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption