ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability
ZDI detailed an uninitialized memory flaw in Oracle VirtualBox's VirtioSCSI (CVE-2026-71132) allowing local attackers to disclose sensitive information.
Zero Day Initiative published ZDI-26-640, a CVSS 5.3 information disclosure vulnerability in the VirtioSCSI component of Oracle VirtualBox. An attacker must first run high-privileged code on the guest system before the uninitialized memory issue can be used to disclose sensitive information. The flaw is tracked as CVE-2026-71132. The advisory reports no exploitation activity.
ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.
Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.
ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability
ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.
Zero Day Initiative published advisory ZDI-26-644 describing a race condition in Oracle VirtualBox's VMSVGA component. Local attackers who already execute high-privileged code on the guest system can escalate privileges on affected installations. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60155.
ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.
The Zero Day Initiative published advisory ZDI-26-641 for an out-of-bounds read vulnerability in Oracle VirtualBox's VirtioSCSI component, assigned CVE-2026-71114 with a CVSS score of 6.1. The flaw allows local attackers to disclose sensitive information on affected installations. Exploitation requires an attacker to first obtain the ability to execute high-privileged code on the target guest system.
ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability
ZDI publishes ZDI-26-642 for CVE-2026-60159, an out-of-bounds read local privilege escalation in Oracle VirtualBox IDisplay, rated CVSS 7.5.
Zero Day Initiative published advisory ZDI-26-642 describing an out-of-bounds read in Oracle VirtualBox's IDisplay component that enables local privilege escalation. Attackers must first obtain the ability to execute high-privileged code on the target guest system. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60159.
ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.
Zero Day Initiative published advisory ZDI-26-643 describing an out-of-bounds read in Oracle VirtualBox's VMSVGA component. Local attackers with the ability to execute high-privileged code on the guest system can disclose sensitive information. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-60162.