ZeroHour
Story · 1 source · 6 articlesfirst updated ()

Zero Day Initiative publishes six Oracle VirtualBox advisories (ZDI-26-639 through ZDI-26-644) covering VMSVGA, VirtioSCSI, and IDisplay local guest flaws

What's new: Initial merged summary — no previous story summary existed. This entry consolidates the six ZDI advisories published 2026-09-09 into a single story; no disagreements between the source reports were found.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-09, ZDI disclosed six Oracle VirtualBox vulnerabilities — CVE-2026-71116, CVE-2026-60155, CVE-2026-60159, CVE-2026-60162, CVE-2026-71114, and CVE-2026-71132 — affecting the VMSVGA, IDisplay, and VirtioSCSI components. Three enable local privilege…

The Zero Day Initiative published six advisories for Oracle VirtualBox on 2026-09-09, numbered ZDI-26-639 through ZDI-26-644, all describing local guest-system flaws that require an attacker to first obtain the ability to execute high-privileged code on the guest. In the VMSVGA component, ZDI-26-639 (CVE-2026-71116) is a heap-based buffer overflow enabling local privilege escalation rated CVSS 7.5; ZDI-26-644 (CVE-2026-60155) is a race condition enabling local privilege escalation rated CVSS 7.5; and ZDI-26-643 (CVE-2026-60162) is an out-of-bounds read enabling information disclosure rated CVSS 6.1. In the VirtioSCSI component, ZDI-26-641 (CVE-2026-71114) is an out-of-bounds read enabling information disclosure rated CVSS 6.1, and ZDI-26-640 (CVE-2026-71132) is an uninitialized-memory information disclosure issue rated CVSS 5.3. In the IDisplay component, ZDI-26-642 (CVE-2026-60159) is an out-of-bounds read enabling local privilege escalation rated CVSS 7.5. None of the advisories report exploitation in the wild. The reports do not state affected VirtualBox versions or fixed releases.

  • Six ZDI advisories published 2026-09-09, numbered ZDI-26-639 through ZDI-26-644, all affecting Oracle VirtualBox.
  • ZDI-26-639: heap-based buffer overflow in VMSVGA, CVE-2026-71116, local privilege escalation, CVSS 7.5.
  • ZDI-26-644: race condition in VMSVGA, CVE-2026-60155, local privilege escalation, CVSS 7.5.
  • ZDI-26-642: out-of-bounds read in IDisplay, CVE-2026-60159, local privilege escalation, CVSS 7.5.
  • ZDI-26-643: out-of-bounds read in VMSVGA, CVE-2026-60162, information disclosure, CVSS 6.1.
  • ZDI-26-641: out-of-bounds read in VirtioSCSI, CVE-2026-71114, information disclosure, CVSS 6.1.
  • ZDI-26-640: uninitialized memory issue in VirtioSCSI, CVE-2026-71132, information disclosure, CVSS 5.3.
  • All six flaws are local and require prior execution of high-privileged code on the guest system.

Coverage timeline

  1. · 6d ago
    ZDI Published Advisories· 26
    ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

    ZDI publishes ZDI-26-644 for CVE-2026-60155, a race condition local privilege escalation in Oracle VirtualBox VMSVGA, rated CVSS 7.5.

  2. · 6d ago
    ZDI Published Advisories· 25
    ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

    ZDI publishes ZDI-26-642 for CVE-2026-60159, an out-of-bounds read local privilege escalation in Oracle VirtualBox IDisplay, rated CVSS 7.5.

  3. · 6d ago
    ZDI Published Advisories· 27
    ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

    ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.

  4. · 6d ago
    ZDI Published Advisories· 25
    ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI disclosed CVE-2026-71114, an out-of-bounds read in Oracle VirtualBox VirtioSCSI letting privileged local guest attackers disclose sensitive information.

  5. · 6d ago
    ZDI Published Advisories· 18
    ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

    ZDI detailed an uninitialized memory flaw in Oracle VirtualBox's VirtioSCSI (CVE-2026-71132) allowing local attackers to disclose sensitive information.

  6. · 6d ago
    ZDI Published Advisories· 18
    ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

    ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60155
+2 in the same advisory: …60159 …60162
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
7.5
group max
<1%
  • oracle vm virtualbox
CVE-2026-71116
+2 in the same advisory: …71114 …71132
Heap-Based Buffer Overflow in Oracle VM VirtualBox VMSVGA Enables Local Privilege Escalation

CVE-2026-71116 is a vulnerability in the Core component of Oracle VM VirtualBox, which ZDI describes as a heap-based buffer overflow in the VMSVGA virtual graphics component that can be leveraged for local privilege escalation. It is difficult to exploit and requires a highly privileged attacker with logon to the infrastructure where VirtualBox executes, with no user interaction required. Successful attacks result in takeover of Oracle VM VirtualBox, and because the vulnerability has scope change, impact may extend to additional products beyond VirtualBox itself. Users running Oracle VM VirtualBox 7.2.14 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

Do: Upgrade Oracle VM VirtualBox to the patched release provided in Oracle's Critical Patch Update for this CVE (the specific fixed version is not stated in the available data; verify via Oracle's advisory). Check installed versions with the VirtualBox About dialog or 'VBoxManage --version' and restrict high-privileged local accounts on systems running VirtualBox until patched. Given the low exploitation likelihood, no emergency action is required beyond routine patching.

7.5
group max
<1%
  • Oracle VM VirtualBox (Core) 7.2.14 (the supported version listed as affected by Oracle)
massmillions of installations (VirtualBox has tens of millions of downloads; the share running the affected 7.2.14 release is unknown)