CVE-2026-35245

7.5

Oracle · VM VirtualBox

A core component vulnerability in Oracle VM VirtualBox 7.2.6 allows unauthenticated attackers to trigger a denial of service via RDP.

Executive summary

An unauthenticated attacker with network access can trigger a complete denial of service in Oracle VM VirtualBox 7.2.6 by sending specially crafted RDP requests.

Vulnerability

This is a denial of service vulnerability residing in the core component of Oracle VM VirtualBox. It allows an unauthenticated attacker with network access via the Remote Desktop Protocol to remotely trigger a hang or repeatable crash of the virtualization software.

Business impact

The exploitation of this vulnerability results in the complete loss of availability for the affected virtual machines and the host virtualization environment. With a CVSS base score of 7.5, the risk is significant because the attack requires no user interaction or authentication, potentially leading to widespread operational disruption for any systems exposing the VirtualBox RDP interface to the network.

Remediation

Immediate Action: Review the latest Oracle Critical Patch Update advisory for April 2026 to identify the specific patched release and apply the update immediately.

Proactive Monitoring: Monitor network traffic for anomalous RDP connection attempts or frequent, unexplained crashes of the VirtualBox process on host systems.

Compensating Controls: Restrict access to the VirtualBox RDP interface by implementing network-level access control lists or VPN requirements to ensure only trusted management stations can reach the service.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of exploitation and the potential for complete service disruption, organizations should prioritize patching or restricting network access to the VirtualBox RDP service. Administrators must verify the status of their deployments against the Oracle security advisory and move to a supported, remediated version to restore system availability and security.

More Oracle CVEs

Sources