CVE-2026-21986

7.1

Oracle · VM VirtualBox

A denial of service vulnerability exists in the core component of Oracle VM VirtualBox for Windows, allowing an unauthenticated attacker to crash the application.

Executive summary

An unauthenticated attacker with local access can trigger a complete denial of service in Oracle VM VirtualBox for Windows, severely impacting system availability.

Vulnerability

This is a denial of service vulnerability in the core component of Oracle VM VirtualBox. It allows an unauthenticated attacker, who has already obtained a logon to the infrastructure where the software executes, to cause the application to hang or crash repeatedly.

Business impact

The exploitation of this flaw leads to a complete denial of service for the virtualization host, which can disrupt all virtual machines and services running within that environment. Given the CVSS score of 7.1, this vulnerability poses a significant risk to business continuity, especially for organizations that rely on VirtualBox for critical infrastructure or development workflows. The scope change indicates that the impact may extend beyond the application itself, potentially affecting the stability of the underlying host operating system.

Remediation

Immediate Action: Update Oracle VM VirtualBox to the latest version provided in the January 2026 Oracle Critical Patch Update to resolve the underlying core flaw.

Proactive Monitoring: Monitor system logs for repeated service crashes, unexpected process terminations, or abnormal resource consumption originating from the VirtualBox process.

Compensating Controls: Restrict local logon access to the host machine to only authorized personnel, effectively mitigating the threat from unauthenticated or unauthorized users who might attempt to exploit this locally executable flaw.

Exploitation status

Public Exploit Available: Yes, a public proof of concept has been identified on GitHub.

Analyst recommendation

Organizations utilizing Oracle VM VirtualBox on Windows must prioritize this update, as the ability for an attacker to reliably crash the virtualization environment creates a significant availability risk. Although local access is a prerequisite, the ease of exploitation makes immediate patching the only reliable method to eliminate the risk of service disruption. Ensure that all affected virtualized environments are identified and updated according to the latest vendor security guidance.

More Oracle CVEs

Sources