Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Oracle
PRODUCT: VM VirtualBox
AFFECTED_VERSIONS: 7.2.6
CONFIDENCE: high
MISSING: patch
SOURCES_JSON: [{"url":"https://www.oracle.com/security-alerts/cpuapr2026.html","name":"Oracle Advisory","tags":["vendor-advisory"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:38.607Z
---END_METADATA---
Description Summary:
A core component vulnerability in Oracle VM VirtualBox 7.2.6 allows unauthenticated attackers to trigger a denial of service via RDP.
Executive Summary:
An unauthenticated attacker with network access can trigger a complete denial of service in Oracle VM VirtualBox 7.2.6 by sending specially crafted RDP requests.
Vulnerability Details
CVE-ID: CVE-2026-35245
Affected Software: Oracle VM VirtualBox
Affected Versions: 7.2.6
Vulnerability: This is a denial of service vulnerability residing in the core component of Oracle VM VirtualBox. It allows an unauthenticated attacker with network access via the Remote Desktop Protocol to remotely trigger a hang or repeatable crash of the virtualization software.
Business Impact
The exploitation of this vulnerability results in the complete loss of availability for the affected virtual machines and the host virtualization environment. With a CVSS base score of 7.5, the risk is significant because the attack requires no user interaction or authentication, potentially leading to widespread operational disruption for any systems exposing the VirtualBox RDP interface to the network.
Remediation Plan
Immediate Action: Review the latest Oracle Critical Patch Update advisory for April 2026 to identify the specific patched release and apply the update immediately.
Proactive Monitoring: Monitor network traffic for anomalous RDP connection attempts or frequent, unexplained crashes of the VirtualBox process on host systems.
Compensating Controls: Restrict access to the VirtualBox RDP interface by implementing network-level access control lists or VPN requirements to ensure only trusted management stations can reach the service.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of April 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is considered highly automatable due to the unauthenticated nature of the RDP interaction.
Analyst Recommendation
Given the ease of exploitation and the potential for complete service disruption, organizations should prioritize patching or restricting network access to the VirtualBox RDP service. Administrators must verify the status of their deployments against the Oracle security advisory and move to a supported, remediated version to restore system availability and security.