ZeroHour

CVE-2026-87277

moderate

Unauthenticated RDP Denial-of-Service in Oracle VM VirtualBox 7.2.16

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87277 is a vulnerability in the Core component of Oracle VM VirtualBox that allows an unauthenticated attacker with network access via RDP to cause a hang or repeatedly crash the product, resulting in complete denial of service. The flaw is rated CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), meaning exploitation is easy over the network with no credentials or user interaction, but the impact is limited to availability — there is no indication of confidentiality or integrity compromise. Only the supported version 7.2.16 is listed as affected, and the attack path relies on the product's built-in RDP (VRDP) capability being enabled and reachable from the network. Desktop hypervisor users typically run VRDP disabled or bound to localhost, which limits real-world exposure. The issue is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation.

What to do: Upgrade VirtualBox to the latest release patched in Oracle's Critical Patch Update (any version newer than 7.2.16). If immediate patching is not possible, disable the VM's Remote Display (VRDP) server in VM Settings > Display, or bind it to localhost only and firewall the VRDP port (default TCP 3389) from untrusted networks. Audit hosts running 7.2.16 for repeated VM crashes or hangs as an indicator of attempted exploitation.

Affected
Oracle VM VirtualBox7.2.16
Estimated exposure
moderatelikely thousands to tens of thousands of installations (est.), out of a very large overall VirtualBox user base — Oracle VirtualBox is a free product with a cumulative install/download base in the 100M+ range, but only the single point release 7.2.16 is affected and the attack additionally requires the optional VRDP remote-display server to be enabled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.