ZeroHour
Product

VirtualBox

4 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.

Zero Day Initiative published advisory ZDI-26-643 describing an out-of-bounds read in Oracle VirtualBox's VMSVGA component. Local attackers with the ability to execute high-privileged code on the guest system can disclose sensitive information. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-60162.

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.

The Zero Day Initiative published advisory ZDI-26-641 for an out-of-bounds read vulnerability in Oracle VirtualBox's VirtioSCSI component, assigned CVE-2026-71114 with a CVSS score of 6.1. The flaw allows local attackers to disclose sensitive information on affected installations. Exploitation requires an attacker to first obtain the ability to execute high-privileged code on the target guest system.

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

ZDI publishes ZDI-26-642 for CVE-2026-60159, an out-of-bounds read local privilege escalation in Oracle VirtualBox IDisplay, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-642 describing an out-of-bounds read in Oracle VirtualBox's IDisplay component that enables local privilege escalation. Attackers must first obtain the ability to execute high-privileged code on the target guest system. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60159.

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-644 describing a race condition in Oracle VirtualBox's VMSVGA component. Local attackers who already execute high-privileged code on the guest system can escalate privileges on affected installations. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60155.

Related CVEs

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:
    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability…
    · oracle vm virtualbox
  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:
    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability…
    · oracle vm virtualbox
  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:
    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and…
    · oracle vm virtualbox
  • Out-of-Bounds Read Information Disclosure in Oracle VM VirtualBox VirtioSCSI
    CVE-2026-71114 is an information disclosure vulnerability in the Core component of Oracle VM VirtualBox; the ZDI advisory characterizes it as an out-of-bounds read in the VirtioSCSI component (Oracle classifies it under CWE-284, improper access control). It is triggered by an attacker who already has a high-privileged logon on the infrastructure where VirtualBox runs, requires no user interaction, and is rated easily exploitable. Successful attacks yield unauthorized access to critical data, potentially all data accessible to VirtualBox, and the scope change means the impact can extend to additional products beyond VirtualBox itself, though integrity and availability are unaffected. Any deployment running the affected 7.2.14 release of the 7.2 branch is exposed, including desktop hosts and test lab servers where users or automation hold privileged local accounts. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%.
    · Oracle VM VirtualBox (Core) 7.2.14 (the only supported version listed as affected)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.