CVE-2026-71130: High severity Oracle Oracle VM VirtualBox vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for triage?
Prioritize Oracle VM VirtualBox deployments running the affected supported version, 7.2.14, where the product can be reached over RDP from a network. The vulnerability is in the Core component.
Does exploitation require credentials or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via RDP, with no user interaction required.
What access could a successful attacker gain?
A successful attack can expose critical data or all data accessible to Oracle VM VirtualBox. It can also allow unauthorized update, insertion, or deletion of some accessible data; the stated impacts are high confidentiality and low integrity impact.