Oracle · Oracle Virtualization · CVE-2026-21987
**Name of the Vulnerable Software and Affected Versions**
Oracle VM VirtualBox versions 7.1.14 and 7.2.4
**Description**
An easily exploitable issue exists in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). A high-privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs can compromise the software. Successful exploitation can lead to a takeover of Oracle VM VirtualBox and may significantly impact additional products.
**Recommendations**
Oracle VM VirtualBox version 7.1.14 should be updated.
Oracle VM VirtualBox version 7.2.4 should be updated.