CVE-2026-21986
BaseFortify
Publication date: 2026-01-20
Last updated on: 2026-01-29
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | vm_virtualbox | 7.1.14 |
| oracle | vm_virtualbox | 7.2.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Oracle VM VirtualBox product, specifically affecting versions 7.1.14 and 7.2.4 on Windows virtual machines. It allows an unauthenticated attacker who has access to the infrastructure where Oracle VM VirtualBox runs to exploit the system. The attacker can cause the Oracle VM VirtualBox to hang or crash repeatedly, resulting in a denial of service (DoS).
How can this vulnerability impact me? :
The vulnerability can lead to a complete denial of service (DoS) of Oracle VM VirtualBox on Windows VMs, causing the system to hang or crash frequently. This disrupts availability and can affect not only Oracle VM VirtualBox but also other related products due to the scope change.