CVE-2026-87270
largeLocal Privilege Escalation in Oracle VM VirtualBox 7.2.16 (Windows Hosts)
CVE-2026-87270 is a local privilege escalation vulnerability in the Core component of Oracle VM VirtualBox, affecting supported version 7.2.16 on Windows hosts only. It is easily exploitable by a low-privileged attacker who already has a logon on the machine where VirtualBox executes, requiring no user interaction. Successful exploitation allows the attacker to compromise and take over Oracle VM VirtualBox, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). In practice, this means any standard user account on a Windows host running the vulnerable version could pivot into full control of the hypervisor and its virtual machines. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently observed.
What to do: Upgrade VirtualBox on Windows hosts from 7.2.16 to the latest release provided in Oracle's Critical Patch Update. Because exploitation requires only a low-privileged local account, minimize and audit local user accounts on machines that run VirtualBox, and check Windows hosts for unexpected VirtualBox process or driver activity.
| Oracle VM VirtualBox | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.